Back to skill

Security audit

ZM PPT/Deck 正式生产流程

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly supports deck production, but its global rules can impose a specific academy logo and insurance-event footer on generated presentations.

Review and edit the branding standards before installing or using this skill for client or non-Zhumeng decks. Confirm any logo, footer, QR code, upload destination, and token/link retention explicitly, and avoid running the PPTX inspection script on confidential decks unless local JSON/stdout output is acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
standards/post-process-elements-standard-v1.md:16
Finding

Mandatory Organization-Specific Branding Hijacks Generated Deck Outputs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (28)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding shows a second description-behavior mismatch: instead of only orchestrating a production pipeline, the skill reportedly inspects/parses existing PPTX files, extracts slide text and media counts, and emits JSON-style analysis. In a deck-production context, that is more dangerous because presentations often contain confidential business content, speaker notes, customer data, and proprietary visuals, so undisclosed parsing and reporting can expose sensitive information or enable unreviewed data handling.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding shows a second description-behavior mismatch: instead of only orchestrating a production pipeline, the skill reportedly inspects/parses existing PPTX files, extracts slide text and media counts, and emits JSON-style analysis. In a deck-production context, that is more dangerous because presentations often contain confidential business content, speaker notes, customer data, and proprietary visuals, so undisclosed parsing and reporting can expose sensitive information or enable unreviewed data handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill description is written entirely in Chinese and presents the skill as a general-purpose PPT production workflow, but it does not state that Chinese output is optional or limited to a China-specific/regulatory context. This can indicate a locale policy issue because the skill appears to impose a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill appears to have file-writing capability without declaring any explicit tool scope or permissions, which breaks least-privilege expectations and makes it harder to review what the skill can actually do. In a production workflow that handles PPTX assets, delivery packages, and uploads, undeclared write access increases the risk of unintended file modification, data corruption, or misuse of local resources.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file uses Chinese throughout, including the title and checklist items, which can amount to forcing a specific language for users without any opt-in or explanation. Under the policy rule, language-specific content should either offer user choice or clearly justify the locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document title and all checklist content are written exclusively in Chinese, which indicates a fixed language choice in the skill artifact. There is no visible note that the skill is China-specific or that users may opt into another language, which can violate a language/locale choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file is entirely written as a fixed Chinese presentation outline, with repeated instructions for specific on-slide wording and no indication that another language may be used based on audience preference. Under the policy rule for natural-language violations, a skill that imposes a single language without opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire skill file is written only in Chinese and provides no indication that users may choose another language or that the locale restriction is intentionally limited to a China-specific audience. Under the policy rules, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script requires specific Chinese directory names and filename keywords such as '成品PPT' and '内容大纲', which effectively enforces a single language/locale. This is a natural-language policy concern because users with differently localized package structures are not given any opt-in, alternative locale handling, or documented justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire standard is written as a Chinese-only instruction set and provides no indication that users may choose another language or locale. Under the policy rule for natural-language violations, forcing a single language without opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file title and the entire instructional content are written exclusively in Chinese, with no indication that language selection is optional or that the skill is region-specific. Per the policy, forcing a specific language without user opt-in can constitute a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains operational guidance only in Chinese and does not indicate that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire standard is written only in Chinese and gives mandatory formatting/content rules without offering any language or locale choice. Under the policy, forcing a specific language without explicit user opt-in is a natural-language policy violation unless clearly documented as a justified locale-specific skill, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file is written entirely as a normative standard in Chinese and explicitly specifies Chinese text limits and Chinese font requirements, such as '微软雅黑 / Microsoft YaHei'. This can constitute a language/locale policy violation because it effectively forces a specific language/locale without any user opt-in or stated region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s instructions and requirements are fully specified in Chinese, which effectively forces a specific language for users or operators consuming this skill. Under the policy, language constraints should either be optional/opt-in or clearly justified as region-specific; neither is stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown template is entirely written in Chinese, including headings and report fields, which implies a fixed output language. Under the policy rules, forcing a specific language without user opt-in or documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill template is written as a Chinese-only instruction set and provides no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all user-facing instructions in a single language and does not offer any language or locale choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The subagent execution prompt is entirely in Chinese and provides no language selection, fallback, or opt-in despite being an operational workflow prompt. In a multilingual environment, this can cause operators or downstream agents to misunderstand gating requirements, delivery criteria, or safety constraints, leading to incorrect execution or bypass of required review steps.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow explicitly instructs uploading a deliverable and then recording file tokens, links, and node identifiers, but provides no guardrails around destination trust, access control, data sensitivity, or user consent. In a production deck pipeline, outputs may contain proprietary client materials, branding assets, or internal content, so normalizing upload and link retention without disclosure controls can lead to unintended data exposure or persistence in external systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The title and the entire protocol are written exclusively in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The checklist states a default preference tied to '野哥偏好' and then says reviews and suggestions should default to a high-density standard. Because the document is written entirely in Chinese and frames this default as a preset user confirmation, it can be interpreted as enforcing a preset preference rather than offering a user choice. This is a natural-language policy concern if the skill is expected to adapt to user language/locale preferences unless explicitly opted in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file contains natural-language instructions and descriptions only in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the language/locale policy rule, forcing a specific language without opt-in can be a policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code reads textual content from presentation slides and prints it to stdout, optionally persisting it to disk as JSON. While the write is part of the script's purpose, there is no inline comment, docstring, or user-facing disclosure warning that the output may contain sensitive document contents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill file is written as a standard titled entirely in Chinese and does not indicate that language is optional or user-selectable. Under the policy rule, forcing a specific language without opt-in can be a natural-language policy violation when no locale justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.