Back to skill

Security audit

Pptx Generator

Security checks for vulnerabilities and agentic risk

Overview

This PowerPoint skill mostly does what it says, but its unpinned global package installation instructions are broader and riskier than necessary.

Install only in an isolated project or disposable environment. Prefer local, pinned dependencies instead of the documented global npm installs, and check output paths before generation or template edits to avoid overwriting existing work.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:247
Finding

Unpinned and Globally Installed Third-Party Dependencies

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest advertises very broad trigger terms such as 'presentation', 'slide', and 'deck', which can match common user requests beyond the narrow intent of PPTX file handling. This can cause the skill to activate unexpectedly in unrelated contexts, increasing the chance of unintended file operations or inappropriate delegation to this skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to create slide files, compile them, and write a final PPTX to fixed paths, but it does not require confirming with the user before creating or overwriting artifacts. In an agentic environment, this can lead to unintended modification of workspace contents or clobbering existing presentation files if names or directories already exist.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description embeds a trigger list containing very common terms like 'presentation', 'slide', 'deck', and 'slides', which can cause the skill to activate in many ordinary conversations unrelated to a user explicitly requesting PowerPoint generation. In an agentic environment, overbroad triggering can route user content into file-generation or file-processing workflows unexpectedly, increasing the chance of unintended actions or exposure of sensitive content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file instructs the agent to delete slides and remove orphaned files as part of editing an existing presentation. Although operational steps are clear, there is no warning that these actions can permanently remove presentation content if applied incorrectly, which is a user-data-impacting behavior for markdown files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The document specifies "English font" and "Chinese font" requirements as fixed defaults, including Microsoft YaHei for Chinese, without indicating that users may choose alternatives based on locale or preference. This can constitute a language/locale policy issue because it imposes locale-specific presentation choices without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The subagent directive hard-codes "Chinese = Microsoft YaHei, English = Arial" as a must-follow instruction, which enforces language-specific formatting without presenting user choice. Because the policy applies to natural-language locale constraints across all file types, this fixed assignment should be opt-in or clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file includes a natural-language rule that ties Chinese-language content to a specific font choice. Because the policy category covers language or locale constraints and the text does not present this as optional or user-selected, it can be read as forcing a locale-specific default without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The XML examples specify lang="en-US" for text runs, which can imply a forced language/locale setting in the generated presentation. The file does not indicate that locale should be chosen based on user content or template context, nor does it justify an English-US-only constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file includes example code that writes a presentation to disk via pres.writeFile({ fileName: "Presentation.pptx" }), but the surrounding documentation does not warn that running the snippet will create or potentially overwrite a local file. Under the markdown-specific warning rule, user-visible disclosure is expected for behaviors that affect user data or filesystem state.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.