Back to skill

Security audit

mckinsey-library

Security checks for vulnerabilities and agentic risk

Overview

This consulting skill is mostly coherent, but it can process client materials, conduct external web research, and add its own branding to generated decks without enough explicit user control or privacy guardrails.

Install only if you are comfortable letting the skill process consulting/client materials and perform web research. Before using it with confidential data, require explicit approval before any external search, redact client names and sensitive facts from queries, and review generated PPT footers for unwanted “麦肯锡资料库顾问 · 内部汇报稿” branding.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
assets/pptx_primitives.py:81
Finding

Unrequested Skill Branding Injected into Customer Presentations

Content
View full analysis

Vulnerability Details

File Location: assets/pptx_primitives.py, lines 81 and 142–146
Vulnerability Type: Skill-controlled output manipulation
Risk Level: High

Vulnerable Code

python
def __init__(self, brand='麦肯锡资料库顾问', width=SW, height=SH):
    self.prs = Presentation()
    self.prs.slide_width = Inches(width)
    self.prs.slide_height = Inches(height)
    self.blank = self.prs.slide_layouts[6]
    self.brand = brand
    self.W, self.H = width, height
python
def footer(self, s, source='', page=None):
    self.rect(s, 0, self.H-0.32, self.W, 0.32, fill=COL['LIGHT'])
    left = f'{self.brand} · 内部汇报稿'
    self.txt(s, 0.55, self.H-0.32, 9.5, 0.32,
             [{'text':left,'size':8.5,'color':COL['GRAY'],'font':FONT['BODY']}],
             anchor=MSO_ANCHOR.MIDDLE)

Technical Analysis

The Deck constructor assigns a Skill-controlled brand as its default value. The footer() method subsequently writes that value into generated presentation slides. Because the default applies without explicit user approval, customer-facing files can receive Skill attribution even when the user did not request or authorize it.

The workflow in SKILL.md directs the agent to use this bundled rendering engine when producing presentations. Therefore, ordinary use of the declared presentation-generation functionality can activate the branding behavior. This alters the content of the deliverable rather than merely controlling an internal implementation detail.

Attack Path

  1. A user asks the Skill to generate a presentation.
  2. The workflow selects the bundled pptx_primitives.py rendering engine.
  3. Presentation code creates Deck() without supplying an explicitly approved brand.
  4. The constructor silently selects the hard-coded Skill brand.
  5. Calls to footer() insert that brand into presentation slides.
  6. The resulting branded presentation is delivered to the user and may subsequently be shared with third parties.

No elevated ...[truncated 703 chars]

Remediation
View remediation

Remediation Suggestions

  1. Change the constructor default to an empty or neutral value:
python
def __init__(self, brand='', width=SW, height=SH):
    ...
  1. Render branding only when the user has explicitly requested or approved it:
python
if self.brand:
    left = self.brand
else:
    left = ''
  1. Obtain organization and attribution text from user-provided presentation requirements rather than from Skill-owned defaults.

  2. Separate neutral document metadata, such as confidentiality status, from promotional or author-attribution text.

  3. Add automated tests that generate a presentation with default settings and verify that no Skill name, vendor name, or other unapproved attribution appears in slide text.

  4. Document branding as an opt-in feature and require confirmation before adding it to customer-facing files.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (28)

Ae3

High
Category
analysis-evasion
Confidence
90% confidence
Finding

Text artifact contains embedded NUL bytes

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/materials_index.md (reported line 55)May include surrounding context.

md
- **36 为外部年度回顾解读文**(麦肯锡《2025全球银行业年度回顾》中文二手解读,与 35 同源同份报告,非百度网盘资料库文件):聚焦"多智能体系统=数字同事/原子智能体"运营重构范式。提炼「运营成本占比60%-70%」「AI降本70%/整体15-20%」「AI投入350亿→1000亿美元」「规模化银行<10%」「十大转型战场+九类原子智能体」「分场景量化(开户/信贷/支付/金融犯罪/财务/共享中心)」,落 functional_playbooks 模块 M 新增子段 M.1。与 35 互补不重复(35=深度简化框架,36=多智能体落地数字)。
- **37 为外部年度报告解读文**(麦肯锡《2025全球银行业年度报告》中文二手解读,与 35/36 同源同份报告,非百度网盘资料库文件):提取标志性主题「精准经营(Precision Banking)」——AI 时代精准而非规模才是制胜利器。提炼「2024全球银行业利润1.2万亿美元创纪录」「中国银行业三大压力(需求放缓/息差走低/风险成本升)」「2025-11 A股最出色银行P/B=平均1.64倍/最低3.22倍(好银行溢价锚点)」「六点精准经营建议(客群/产品/技术/风险/人才/资源配置)」,落 functional_playbooks 模块 M 新增子段 M.2。与 35/36 互补不重复(35=深度简化框架,36=多智能体落地数字,37=精准经营制胜利器+六建议,且直接对应《某股份制银行客群分群经营策略》PPT 的精准客群经营主线)。
- **38 为外部署名观点文**(麦肯锡中国区金融机构咨询业务负责人 周宁人 署名,非百度网盘资料库文件):聚焦"移动银行即战略中枢(超级服务入口)"。提炼 Finalta 基准数据(应用内解决>80%日常事务/交互频次+51%/移动端销售获客近2倍/头部vs落后2.3倍·区域最大1.7倍·成败在执行力/预测准确率约90%)+ 四项关键能力(无缝设计/深度个性化/预测性互动/智能导航)+ 智能数据核心(需求预判+主动引导)+ 两条推进路径(销售引擎/一步到位平台)。落 functional_playbooks 模块 M 新增子段 M.3。与 35/36/37 互补不重复(35=深度简化框架,36=多智能体落地数字,37=精准经营制胜利器,38=前台主阵地·移动银行战略中枢+数字化获客+千人千面+预测性互动),且直接对应《某股份制银行客群分群经营策略》PPT 的"数字获客+千人千面+预测性互动"策略线与交叉销售战略 渠道转型。
- **39 为外部区域银行观察文**(麦肯锡区域型银行 GenAI 应用观察,与 35/36/37/38 同源同份 2025 报告口径,非百度网盘资料库文件):切"区域型银行/中型银行"视角。提炼「真实头部案例(摩根士丹利1.5万顾问/ING 10市场3700万客户)」「四点观察(内部→客户端延展/多智能体一站式/未来三年利润率影响60%-80%·潜在生产力2000-3400亿/隐性门槛40%企业50+数据孤岛·2030中国AI人才缺口500万)」「六大高价值场景(信用风险管理/RM copilot/软件提效/智能客服/超个性化/知识中枢)」「多智能体协同(copilot分派分析/策略/合规三智能体,单客户经理覆盖+5%-15%·单客收入+5%-10%)」「三类布局模式(建造者/革新者/采用者·90%银行建企业级AI堆栈)」「三维破局路径(路径选择/战略融合:联邦学习数据可用不可见+监管规则转可计算逻辑单元+LoRA微调/生态协同)」,落 functional_playbooks 模块 M 新增子段 M.4。与 35/36/37/38 互补不重复(35=深度简化框架,36=多智能体落地数字,37=精准经营制胜利器,38=移动银行战略中枢,39=区域型银行视角+AI场景库+布局模式),且直接对应《某股份制银行客群分群经营策略》PPT 的"交叉销售战略/区域银行差异化/高价值AI场景聚焦"线。
- **40 为外部出海金融观察文**(麦肯锡中国企业出海 + 商业银行国际业务能力建设观察,非百度网盘资料库文件):切"中国企业出海 / 出海金融 / 商业银行国际业务"视角。提炼「机会锚点(进出口近6万亿美元·年增4%/向东盟直接投资+35%·2023区域流量东盟+34.7%欧盟-6.1%美国-5.2%澳洲-80.4%/进出口CAGR3.6%·ODI CAGR4.1%/东部沿海占ODI 82%·同比+14.3%·浙粤沪前三/京津冀长三角大湾区近5年进出口CAGR 6%·7%·1%)」「国际业务三阶段能力演进框架(跨境结算→海外渠道落地→本地化全球运营)」「跨境客群抓手(跨境电商2.6万亿元·年增13%·>60%中小微
...[truncated 26 chars]

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/materials_index.md (reported line 55)May include surrounding context.

md
- **36 为外部年度回顾解读文**(麦肯锡《2025全球银行业年度回顾》中文二手解读,与 35 同源同份报告,非百度网盘资料库文件):聚焦"多智能体系统=数字同事/原子智能体"运营重构范式。提炼「运营成本占比60%-70%」「AI降本70%/整体15-20%」「AI投入350亿→1000亿美元」「规模化银行<10%」「十大转型战场+九类原子智能体」「分场景量化(开户/信贷/支付/金融犯罪/财务/共享中心)」,落 functional_playbooks 模块 M 新增子段 M.1。与 35 互补不重复(35=深度简化框架,36=多智能体落地数字)。
- **37 为外部年度报告解读文**(麦肯锡《2025全球银行业年度报告》中文二手解读,与 35/36 同源同份报告,非百度网盘资料库文件):提取标志性主题「精准经营(Precision Banking)」——AI 时代精准而非规模才是制胜利器。提炼「2024全球银行业利润1.2万亿美元创纪录」「中国银行业三大压力(需求放缓/息差走低/风险成本升)」「2025-11 A股最出色银行P/B=平均1.64倍/最低3.22倍(好银行溢价锚点)」「六点精准经营建议(客群/产品/技术/风险/人才/资源配置)」,落 functional_playbooks 模块 M 新增子段 M.2。与 35/36 互补不重复(35=深度简化框架,36=多智能体落地数字,37=精准经营制胜利器+六建议,且直接对应《某股份制银行客群分群经营策略》PPT 的精准客群经营主线)。
- **38 为外部署名观点文**(麦肯锡中国区金融机构咨询业务负责人 周宁人 署名,非百度网盘资料库文件):聚焦"移动银行即战略中枢(超级服务入口)"。提炼 Finalta 基准数据(应用内解决>80%日常事务/交互频次+51%/移动端销售获客近2倍/头部vs落后2.3倍·区域最大1.7倍·成败在执行力/预测准确率约90%)+ 四项关键能力(无缝设计/深度个性化/预测性互动/智能导航)+ 智能数据核心(需求预判+主动引导)+ 两条推进路径(销售引擎/一步到位平台)。落 functional_playbooks 模块 M 新增子段 M.3。与 35/36/37 互补不重复(35=深度简化框架,36=多智能体落地数字,37=精准经营制胜利器,38=前台主阵地·移动银行战略中枢+数字化获客+千人千面+预测性互动),且直接对应《某股份制银行客群分群经营策略》PPT 的"数字获客+千人千面+预测性互动"策略线与交叉销售战略 渠道转型。
- **39 为外部区域银行观察文**(麦肯锡区域型银行 GenAI 应用观察,与 35/36/37/38 同源同份 2025 报告口径,非百度网盘资料库文件):切"区域型银行/中型银行"视角。提炼「真实头部案例(摩根士丹利1.5万顾问/ING 10市场3700万客户)」「四点观察(内部→客户端延展/多智能体一站式/未来三年利润率影响60%-80%·潜在生产力2000-3400亿/隐性门槛40%企业50+数据孤岛·2030中国AI人才缺口500万)」「六大高价值场景(信用风险管理/RM copilot/软件提效/智能客服/超个性化/知识中枢)」「多智能体协同(copilot分派分析/策略/合规三智能体,单客户经理覆盖+5%-15%·单客收入+5%-10%)」「三类布局模式(建造者/革新者/采用者·90%银行建企业级AI堆栈)」「三维破局路径(路径选择/战略融合:联邦学习数据可用不可见+监管规则转可计算逻辑单元+LoRA微调/生态协同)」,落 functional_playbooks 模块 M 新增子段 M.4。与 35/36/37/38 互补不重复(35=深度简化框架,36=多智能体落地数字,37=精准经营制胜利器,38=移动银行战略中枢,39=区域型银行视角+AI场景库+布局模式),且直接对应《某股份制银行客群分群经营策略》PPT 的"交叉销售战略/区域银行差异化/高价值AI场景聚焦"线。
- **40 为外部出海金融观察文**(麦肯锡中国企业出海 + 商业银行国际业务能力建设观察,非百度网盘资料库文件):切"中国企业出海 / 出海金融 / 商业银行国际业务"视角。提炼「机会锚点(进出口近6万亿美元·年增4%/向东盟直接投资+35%·2023区域流量东盟+34.7%欧盟-6.1%美国-5.2%澳洲-80.4%/进出口CAGR3.6%·ODI CAGR4.1%/东部沿海占ODI 82%·同比+14.3%·浙粤沪前三/京津冀长三角大湾区近5年进出口CAGR 6%·7%·1%)」「国际业务三阶段能力演进框架(跨境结算→海外渠道落地→本地化全球运营)」「跨境客群抓手(跨境电商2.6万亿元·年增13%·>60%中小微
...[truncated 26 chars]

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly promotes autonomous external data collection and autonomous generation of deliverables from client materials, but it does not warn users about transmitting potentially sensitive client content to external sources, verifying authorization, or limiting system actions. In a consulting skill that processes documents, notes, meeting records, and then performs web research and file generation, missing privacy and operational guardrails materially increases the risk of data leakage, policy violations, and unintended actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description lists activation phrases such as “帮我做咨询方案”, “根据资料出 PPT”, “结构化客户输入”, and “做图表/可视化”, which are broad requests that could easily appear in ordinary user conversation. The file does not provide narrowing conditions, exclusions, or negative examples to clarify when this skill should activate versus when a more general skill should handle the request.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

文档在 L109、L116、L174 已多次声明每页标题应为“行动型标题/结论句”,但 L126 又明确写“行动型标题只中性设问,让结论藏在图里”。这不是简单遗漏,而是对同一输出物标题意图的直接矛盾,会影响技能是否按声明的方法生成咨询页。

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · assets/__primitives_selftest__.pptx!/ppt/printerSettings/printerSettings1.bin (reported line 2)May include surrounding context.

text
�<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
	<key>com.apple.print.PageFormat.PMHorizontalRes</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · assets/__primitives_selftest__.pptx!/ppt/printerSettings/printerSettings1.bin (reported line 3)May include surrounding context.

text
�<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
	<key>com.apple.print.PageFormat.PMHorizontalRes</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · assets/__primitives_selftest__.pptx!/ppt/printerSettings/printerSettings1.bin (reported line 233)May include surrounding context.

text
�<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
	<key>com.apple.print.PageFormat.PMHorizontalRes</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · assets/__primitives_selftest__.pptx!/ppt/printerSettings/printerSettings1.bin (reported line 236)May include surrounding context.

text
�<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
	<key>com.apple.print.PageFormat.PMHorizontalRes</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · assets/__primitives_selftest__.pptx!/ppt/printerSettings/printerSettings1.bin (reported line 237)May include surrounding context.

text
�<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
	<key>com.apple.print.PageFormat.PMHorizontalRes</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · assets/__primitives_selftest__.pptx!/ppt/printerSettings/printerSettings1.bin (reported line 331)May include surrounding context.

text
�<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
	<key>com.apple.print.PageFormat.PMHorizontalRes</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · assets/__primitives_selftest__.pptx!/ppt/printerSettings/printerSettings1.bin (reported line 2)May include surrounding context.

text
�<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
	<key>com.apple.print.PageFormat.PMHorizontalRes</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · assets/__primitives_selftest__.pptx!/ppt/printerSettings/printerSettings1.bin (reported line 236)May include surrounding context.

text
�<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
	<key>com.apple.print.PageFormat.PMHorizontalRes</key>

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module description, branding, and font defaults are all hard-coded for Chinese usage, including Chinese-only instructional text and default fonts such as 楷体 and 微软雅黑. The policy requires flagging language or locale constraints when the skill forces a specific language without offering user choice or documenting an opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire checklist, prompt template, statuses, and workflow instructions are presented only in Chinese, with no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-language environment. Per the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s operational instructions, headings, and requirements are all presented in Chinese, which effectively forces a specific language for use of the skill. The policy allows locale constraints only when the skill offers user choice or clearly documents a justified region-specific limitation, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file opens with a Chinese-only title and the entire playbook is written as Chinese operating guidance, which effectively constrains the skill's language/locale behavior. There is no indication that users may opt into another language or locale, so this can violate the requirement not to force a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file is written as an instruction protocol entirely in Chinese, beginning with a Chinese-only title, with no indication that users may choose another language or locale. Under the policy rule, forcing a specific language without opt-in is a natural-language policy concern unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file is entirely written in Chinese and includes usage directives for the skill, but it does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-language context. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains user-facing instructions exclusively in Chinese from start to finish. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The title and usage instructions are written entirely in Chinese and direct routing to this file for relevant engagements, implying the skill content is expected to be used in Chinese by default. There is no indication that users may choose another language or that the Chinese-only constraint is justified by a region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README labels the skill in Chinese and the usage example is also Chinese, with no indication that users may interact in other languages or opt into a locale preference. Under SQP-3, forcing or implicitly constraining language without user choice can be a natural-language policy issue unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The code persists a generated presentation via self.prs.save(path) and the self-test writes __primitives_selftest__.pptx, but this file does not include a confirmation prompt, user-facing log around the write action, or comments/docstrings warning that it creates files on disk. For code files, file writes can warrant a missing-warning finding when there is no visible disclosure in the code and the action is not explicitly surfaced to the user.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.