Back to skill

Security audit

academic-presentation-学术汇报全自动化-只需提供论文(PDF 或文本),即可自动生成翻译稿、总结稿、PPT 和演讲稿,所有文件完成后自动发送到微信

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent, but it automatically sends research materials to external services and WeChat while also making an inaccurate privacy claim.

Review before installing. Use this only for papers you are comfortable sending to a selected PPT provider and then to WeChat, or choose the skip/local-only path and confirm no messaging occurs. Do not use it for confidential, embargoed, unpublished, or restricted papers unless the external upload and WeChat delivery behavior is corrected or explicitly disabled.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
README.md:207
Finding

Misleading Privacy Claim Despite Third-Party Document Submission

Content
View full analysis

Vulnerability Details

File Location: README.md:207-212, with the contradictory upload workflow documented in SKILL.md:108-133
Vulnerability Type: Misleading privacy disclosure
Risk Level: Medium

Vulnerable Code Snippets

Privacy statement in README.md:207-212:

markdown
## 🔐 安全说明

- ❌ **不嵌入**任何第三方 API Key
- ✅ API Key 由用户在配置阶段自行输入
- ✅ 仅保存在用户本地配置中
- ✅ 不会上传到任何第三方服务器

Contradictory third-party submission workflow in SKILL.md:108-133:

markdown
#### 方案 A:anygen(推荐)
```bash
# 1. 准备任务
anygen task prepare --data '{"operation":"slide","messages":[{"role":"user","content":{"text":"[PPT需求]"}}]}'

# 2. 从响应获取 suggested_task_params,创建任务
anygen task create --data '{"operation":"slide","prompt":"[final_prompt]"}'

# 3. 轮询等待完成(可能需要几分钟)
anygen task get --params '{"task_id":"<id>"}' --wait --timeout 600000

# 4. 下载
anygen task +download --task-id <id> --output-dir /tmp/academic-ppt/

方案 B:gamma.app

bash
# 使用 gamma API(需用户提供 API Key)
curl -X POST https://api.gamma.app/v1/presentations \
  -H "Authorization: Bearer $GAMMA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"title":"[Doc_Title]","slides":[...]}'
text

### Technical Analysis

The README explicitly claims that data will not be uploaded to any third-party server. However, the prescribed presentation-generation workflow sends paper-derived information to Anygen or Gamma. The submitted data includes the presentation requirements or final prompt and, for Gamma, the document title and slide content.

Use of an external presentation service is part of the advertised functionality and is not inherently malicious. The security problem is the inaccurate privacy representation: users may provide confidential material believing it remains local when the workflow necessarily discloses derived content to an external provider.

This finding is limited to misleading disclosure. The audited package co
...[truncated 1420 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the assertion that content is never uploaded to third-party servers.
  2. Clearly state that selecting Anygen or Gamma transmits paper-derived prompts, titles, slide outlines, and presentation content to that provider.
  3. Request explicit user confirmation immediately before each external submission, showing the provider and categories of data to be sent.
  4. Make skip the default provider for documents classified as confidential, unpublished, embargoed, or sensitive.
  5. Provide a local-only workflow that generates translation, summary, outline, and speech-note files without invoking an external presentation service.
  6. Link to each provider's privacy, retention, training-use, and deletion policies so users can make an informed decision.
  7. Minimize transmitted data by removing unnecessary identifiers and sending only the content required for slide generation.
  8. Update README.md, SKILL.md, and package metadata so all privacy disclosures consistently describe both third-party PPT submission and subsequent WeChat delivery.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (18)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README states that the skill will not upload data to any third-party server, yet earlier sections explicitly describe sending content to external PPT generation APIs such as anygen.io or gamma.app. This is a material contradiction that can mislead users about where their paper content goes, creating a serious privacy and informed-consent issue, especially for unpublished or sensitive research.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The top-level description states that generated materials will be automatically sent to WeChat but does not present a clear privacy warning or informed-consent requirement. This is dangerous because users may provide unpublished papers, proprietary research, or personally identifying content without understanding that the data will be transmitted off-platform.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Stage 7 instructs the skill to automatically send all generated files to the 'openclaw-weixin' channel without a mandatory consent gate immediately before transmission. This creates a direct data-exfiltration path for potentially sensitive academic content, especially since the output bundle includes translated text, summaries, PPTs, and speech notes.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest advertises automatic sending of generated files to WeChat but does not provide any warning, consent language, or disclosure about data transmission to an external platform. Since the inputs are academic papers that may be unpublished, copyrighted, or confidential, automatic export materially increases the risk of unintended data leakage and privacy violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README describes the translation output as a full Chinese translation and presents Chinese-language output as the default workflow behavior. While one example asks whether translation is needed, the overall description does not clearly present language choice as an explicit user option for all outputs, which can be read as forcing a specific locale without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README prominently advertises automatic sending of generated files to WeChat but does not place an equally clear warning near that claim that documents will be transmitted through a messaging channel. Because outputs may contain full paper text, translations, summaries, and notes, this can lead to unintentional disclosure of sensitive or unpublished research materials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README documents use of external PPT APIs but does not clearly warn users that paper content or derived summaries may be sent to those third-party services. In an academic context, this is risky because papers may be unpublished, proprietary, or subject to confidentiality restrictions, so hidden data transfer can cause compliance and privacy problems.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase '帮我做PPT' is broad enough to match ordinary conversation unrelated to this specific skill, increasing the chance of accidental activation. In this skill's context, accidental invocation can cause users to disclose documents, configure external API keys, or initiate data-transfer workflows they did not intend to run.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises broad natural-language trigger phrases like '做PPT' and '论文演讲' directly in the description, which increases the chance of accidental or overly easy invocation outside a narrowly intended context. Because this skill performs multi-step document processing and eventual external transmission to WeChat, ambiguous activation raises the risk of unintended handling of sensitive papers or drafts.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
anygen task prepare --data '{"operation":"slide","messages":[{"role":"user","content":{"text":"[PPT需求]"}}]}'

# 2. 从响应获取 suggested_task_params,创建任务
anygen task create --data '{"operation":"slide","prompt":"[final_prompt]"}'

# 3. 轮询等待完成(可能需要几分钟)
anygen task get --params '{"task_id":"<id>"}' --wait --timeout 600000

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
anygen task prepare --data '{"operation":"slide","messages":[{"role":"user","content":{"text":"[PPT需求]"}}]}'

# 2. 从响应获取 suggested_task_params,创建任务
anygen task create --data '{"operation":"slide","prompt":"[final_prompt]"}'

# 3. 轮询等待完成(可能需要几分钟)
anygen task get --params '{"task_id":"<id>"}' --wait --timeout 600000

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The referenced gamma.app endpoint confirms that the skill depends on an external network destination for presentation generation, which expands the exposure surface for user content and API credentials. In this context, the danger is elevated because the workflow handles full academic documents and may send their distilled content to a third party without sufficiently prominent privacy controls.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

方案 B:gamma.app

bash
# 使用 gamma API(需用户提供 API Key)
curl -X POST https://api.gamma.app/v1/presentations \
  -H "Authorization: Bearer $GAMMA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"title":"[Doc_Title]","slides":[...]}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The referenced gamma.app endpoint confirms that the skill depends on an external network destination for presentation generation, which expands the exposure surface for user content and API credentials. In this context, the danger is elevated because the workflow handles full academic documents and may send their distilled content to a third party without sufficiently prominent privacy controls.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

方案 B:gamma.app

bash
# 使用 gamma API(需用户提供 API Key)
curl -X POST https://api.gamma.app/v1/presentations \
  -H "Authorization: Bearer $GAMMA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"title":"[Doc_Title]","slides":[...]}'

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The quick-trigger list contains short, common phrases that could match ordinary user requests without clearly signaling that a high-impact automation workflow will run. In context, accidental activation is more dangerous because the skill can create files, call third-party PPT services, and automatically send outputs to WeChat.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The display name, tagline, description, and trigger phrases are entirely in Chinese, with no indication that other languages are supported or that the user can opt into this locale. This can constitute a language/locale policy issue because the skill appears to enforce a specific language experience without documenting a choice or justified regional limitation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad natural-language phrases such as “做PPT” that can plausibly appear in ordinary conversation, increasing the chance the skill activates when the user did not intend to invoke this workflow. Because the skill performs multi-step document processing and can send outputs to WeChat, accidental activation could expose sensitive paper contents or initiate unwanted external actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description states the workflow will convert papers into translated materials, which implies a fixed language/locale behavior without any visible user opt-in or configuration for translation direction. While not inherently malicious, forcing language behavior can cause unauthorized transformation of user content, incorrect outputs, or privacy/compliance issues when users did not request translation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes very common phrases such as '做PPT', '学术PPT', and '汇报PPT', which can match many ordinary user requests and cause the skill to activate outside narrowly intended contexts. Because this skill performs high-impact automated actions and may send generated materials to WeChat, broad activation increases the chance of unintended execution, data processing, or exfiltration-like behavior without clear user intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.