Back to skill

Security audit

Skill Ppt Builder

Security checks for vulnerabilities and agentic risk

Overview

This PPT-building skill mostly does what it says, but it can send full slide prompts to third-party image APIs while also claiming there is no external SaaS dependency.

Install only if you are comfortable sending slide prompts and deck content to Ofox or OpenRouter. Do not use it for confidential, regulated, customer, financial, or unreleased business material unless you have approval and understand the provider's data handling. Use a virtual environment and pin dependencies before installing python-pptx.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_deck.py:43
Finding

Insufficiently Disclosed Transmission of Presentation Content to Third-Party APIs

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:239
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims an end-to-end workflow and 'no external SaaS dependency' while the instructions explicitly rely on external API gateways/providers such as Ofox/OpenRouter and a Gemini-based image model. This mismatch is security-relevant because operators may trust the skill with sensitive deck content under false assumptions about local-only processing, data handling, and review coverage.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

The skill instructs deletion of files as part of a rerun workflow using a raw shell command. Even though the example path is fixed, patterns that normalize destructive shell operations in agent skills are dangerous because parameterization, path substitution, or user-influenced filenames elsewhere in the workflow can lead to unintended deletion of arbitrary files.

Content

Scanner excerpt · SKILL.md (reported line 233)May include surrounding context.

md
python3 scripts/generate_deck.py --start 1 --end 5

    # 4. 重跑某页(删旧图再跑)
    rm scripts/output/slide_03.jpg && python3 scripts/generate_deck.py --start 3 --end 3

    # 5. 生成完自动组装 PPTX
    python3 scripts/generate_deck.py --assemble

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/generate_deck.py (reported line 16)May include surrounding context.

python
python3 generate_deck.py --start 1 --end 5

    # 重跑某一页(先删旧图)
    rm output/slide_03.jpg && python3 generate_deck.py --start 3 --end 3
"""

import json

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill describes capabilities that involve environment access, local file reads, and network/API use, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates an overbroad execution surface where an agent may use more tools than intended, making accidental data access or exfiltration harder to constrain and audit.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The primary skill description is written in Chinese and the workflow later explicitly requires '中文渲染强制要求', indicating a fixed language/locale behavior. The file does not offer the user an opt-in choice of language or explain that the skill is intended only for a Chinese-language context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The global prompt requirements explicitly include a mandatory Chinese-rendering requirement, which imposes a specific language/locale on outputs. Because the document does not provide a user choice or a justified China-specific compliance/business constraint, this is a natural-language policy violation under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction '所有中文文字必须清晰可读' mandates Chinese text rendering as a requirement. Elsewhere the guide repeatedly enforces Chinese-only content handling, but it does not offer an opt-in choice or explain that this skill is intentionally limited to a Chinese-language workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction '纯中文' requires a specific language for generated content, which is a natural-language locale policy constraint. The file does not offer the user a language choice or explain a region-specific reason for forcing Chinese output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file is entirely written in Chinese and presents the checklist as the default operating language, with no indication that users may choose another language or that the skill is limited to a Chinese-language context. Under the policy rule for natural-language violations, forcing a specific language without opt-in is a reportable issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends slide prompts to third-party services (Ofox/OpenRouter) for image generation, and those prompts may contain confidential business content, personal data, or sensitive draft material. Because there is no explicit notice, consent flow, or redaction guidance, users may unintentionally exfiltrate sensitive information off-host.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This code performs outbound transmission to an external image-generation API, carrying user-supplied prompt content and authentication credentials. In the context of a deck-building skill, prompts can easily include proprietary roadmap details, internal strategy, or personal information, so the external transmission is security-relevant and should be treated as data exfiltration risk unless clearly disclosed and controlled.

Content

Scanner excerpt · scripts/generate_deck.py (reported line 52)May include surrounding context.

python
"response_format": "b64_json"
    }).encode("utf-8")
    req = urllib.request.Request(
        "https://api.ofox.ai/v1/images/generations",
        data=payload,
        headers={"Content-Type": "application/json", "Authorization": f"Bearer {api_key}"}
    )

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The requirement to copy source text exactly, combined with the surrounding Chinese-rendering rules, implies a rigid language/locale constraint. The document does not state that this is a Chinese-specific tool or provide any mechanism for users to select another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The document is entirely written in Chinese and presents mandatory writing rules such as banned terms and required placeholder formats, but it does not state that the skill is intended only for Chinese-language content or offer any language/locale opt-in. Under the policy, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language interface exposed by the module docstring, usage text, and CLI help strings is fixed to Chinese. This can violate language/locale policy when the skill does not provide users a choice of language or clearly document that it is intentionally region- or locale-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The style string is written as an instruction in Chinese and explicitly requires that all Chinese text be clearly readable, which imposes a specific language/locale expectation. The file does not offer any user choice or opt-in for language, so this is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.