Back to skill

Security audit

PPT Workflow

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent PPT-generation skill that uses disclosed web search, model routing, and file outputs, with privacy and trigger-scope points users should understand before use.

Before installing, treat this as an external-research and document-generation workflow: do not provide confidential, unpublished, regulated, or proprietary material unless your organization allows those topics to be processed by the configured search tools and models. Review generated citations and delete workspace outputs/backups if they contain sensitive content.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (19)

External Model or Provider Selection

High
Category
Excessive Agency
Content
```bash
# 测试模型
openclaw model test --model qwen3.5
openclaw model test --model kimi-2.5
openclaw model test --model minimax-2.5
```
Confidence
90% confidence
Finding
The documentation explicitly references external model providers and operational testing commands, reinforcing that the skill depends on third-party model routing. In context, this is dangerous because the workflow also includes literature search and content generation stages, yet the file provides no data-classification controls, provider trust boundaries, or restrictions on what may be sent to those external services.

External Model or Provider Selection

High
Category
Excessive Agency
Content
# 测试模型
openclaw model test --model qwen3.5
openclaw model test --model kimi-2.5
openclaw model test --model minimax-2.5
```

### 问题 3: PPT 生成失败
Confidence
90% confidence
Finding
The use of another named external model provider further confirms multi-provider data egress without corresponding safeguards or warnings. Multiple providers increase the attack surface and complicate compliance, auditing, and user understanding of where presentation content, research topics, and attached materials may be transmitted.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad, common-language requests such as '做个 PPT' and 'presentation', which can cause the skill to activate on ordinary user queries without clear intent to invoke this workflow. In this skill's context, unintended activation is more dangerous because later stages explicitly involve external search and multi-model routing, potentially sending user topic details to third-party services without explicit, per-use consent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The workflow description states that content search and multiple external models will be used, but it does not warn users that their provided topics, research areas, and related details may be transmitted to external providers. This creates a privacy and data-governance risk, particularly for confidential presentations, unpublished research, internal business strategy, or regulated data.

Skill Enumeration

Medium
Category
Agent Snooping
Content
| 文件 | 路径 |
|------|------|
| **技能配置** | `skills/ppt-workflow/openclaw.skill.json` |
| **技能说明** | `skills/ppt-workflow/SKILL.md` |
| **快速指南** | `skills/ppt-workflow/README.md` |
| **Agent 配置** | `agents/academic-assistant/agent/config.json` |
| **工作流文档** | `workspace/guides/PPT 工作流_固化配置_v1.0.md` |
Confidence
80% confidence
Finding
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The description highlights end-to-end automation but does not warn users that the skill performs web/literature searches and produces output files. In this context, missing disclosure is risky because users may unknowingly authorize external data retrieval, citation collection, and file creation/export, which can affect privacy, cost, provenance, and trust in generated academic materials.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation phrase "帮我做一个 PPT,主题是:[你的主题]" is broad, natural-language, and likely to overlap with ordinary user requests unrelated to explicitly opting into this skill. That creates a prompt-hijacking/over-trigger risk where the skill may activate unexpectedly and initiate downstream actions such as web/literature search and file generation without sufficiently explicit user intent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README describes automated content search, use of multiple models, and generation of output files, but does not warn users that their topic or supplied materials may be sent to external services or stored in generated artifacts. In a workflow that searches the web and produces files such as PPT, PDF, notes, and bibliographic data, omission of privacy and data-handling warnings can expose sensitive information through external transmission or local persistence without informed consent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrase '帮我做一个 PPT,主题是:[你的主题]' is broad and closely matches normal user conversation, which can cause the skill to activate unintentionally in unrelated contexts. Because this skill performs a multi-stage workflow with web/content search and file generation, accidental activation could lead to unintended data processing, unnecessary external queries, or unexpected artifact creation.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The manifest description is written entirely in Chinese and presents the skill as a general PPT workflow without stating that it is China- or Chinese-only. Because the file does not offer an opt-in language choice or justify a locale restriction, it appears to impose a specific language by default.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill advertises automatic completion of content search and processing through named external models, but does not warn that user-provided topics, source material, or sensitive research content may be transmitted to web search providers and third-party model services. In a presentation-building workflow, users may supply unpublished research, personal data, or confidential institutional material, so lack of disclosure meaningfully increases the risk of unintended data exposure.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrase '只需一句话' with examples like '帮我做一个 PPT,主题是…' is broad enough to match ordinary conversation, which can cause accidental activation of the skill in unrelated chats. Because the skill performs multi-step automation including web search, external model routing, and file generation, unintended invocation could disclose user content to third-party services or create unwanted artifacts.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list includes very generic phrases such as '做个 PPT', '制作 PPT', and 'presentation', which are likely to match ordinary user requests and cause this skill to activate too broadly. Overbroad activation can misroute unrelated conversations into a multi-step workflow with web search and document generation, increasing the chance of unintended execution, user confusion, or unnecessary access to external dependencies.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill name, description, workflow stages, and example inputs are written entirely in Chinese, suggesting the skill is designed to operate in a fixed language without documenting a user-selectable language option. Under the policy, a language constraint should either be optional for the user or clearly documented as a justified locale-specific limitation.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords are broad, generic phrases like '做个 PPT', '制作 PPT', and 'presentation', which can cause the skill to activate for ordinary user requests without clear consent to run a multi-stage workflow. In an agent environment, this increases the risk of over-collection of user data, unnecessary web searches, and unintended file generation or external model routing.

Natural-Language Policy Violations

Low
Confidence
81% confidence
Finding
All instructions, trigger phrases, and usage examples are presented in Chinese, which effectively biases the skill toward a single language experience. The file does not state that the skill is China- or Chinese-language-specific, nor does it offer users an opt-in or alternative language path.

Missing User Warnings

Low
Confidence
92% confidence
Finding
The skill defines a delivery package containing PPTX, PDF, notes, figures, and references, but does not warn users that these artifacts will be written to the workspace and may persist after the session. Presentation files often contain speaker notes, embedded citations, and source figures that can retain sensitive or proprietary information, so silent persistence creates avoidable confidentiality risk.

Natural-Language Policy Violations

Low
Confidence
94% confidence
Finding
This markdown file presents all instructions, labels, and guidance exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue when no alternative language option or justification is provided.

Natural-Language Policy Violations

Low
Confidence
79% confidence
Finding
The manifest presents the skill behavior and user-facing examples in Chinese, but does not state whether users may interact in other languages or whether output language follows user preference. Because this is a general productivity skill rather than a clearly region-specific tool, the lack of language-choice documentation may amount to an implicit language constraint.

Static analysis

No suspicious patterns detected.