Back to skill

Security audit

PowerPoint PPTX Layout Export

Security checks for vulnerabilities and agentic risk

Overview

This is a PowerPoint/PPTX workflow skill with no executable payload, persistence, credential handling, or hidden data movement found.

Installers should treat this as a normal PPTX helper, but use it for explicit PowerPoint deck generation, repair, export, or OOXML inspection tasks. Because deck edits can affect user files, keep the original deck or template untouched and review generated or repaired PPTX output before relying on it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger sentences are so broad and malformed that an orchestrator or user could invoke this skill in situations beyond its intended scope, causing the agent to process or modify PowerPoint content when a more appropriate or safer workflow should have been selected. In an automation context, overbroad activation increases the chance of unintended file handling, destructive edits, or misuse on untrusted PPTX inputs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are extremely broad and partially templated in a way that could match ordinary user requests about PowerPoint help, causing the skill to activate when the user did not explicitly intend to invoke it. In an agent environment, unintended activation can redirect task handling, expose the agent to unreviewed instructions from the skill, or cause actions to be taken under the wrong workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger section uses very broad keywords such as 'creative-and-content', 'pptx', and 'microsoft powerpoint', along with generic example invocations that could match many unrelated requests. This can cause the skill to activate outside its intended scope, leading the agent to apply file-handling, code-generation, or document-repair behaviors in contexts where they were not requested, increasing the chance of unsafe or inappropriate actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The default prompt is broad and, combined with implicit invocation, can cause this skill to trigger for many ordinary PowerPoint-related requests without the user explicitly opting in. That increases the chance the agent will access or transform presentation content unexpectedly, which is a real security and safety issue even if the skill’s functional purpose is legitimate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger sentences are broad, repetitive, and partially templated in a way that could cause the skill to activate on loosely related PowerPoint or presentation-help requests. Unintended invocation can route user tasks into this skill when not appropriate, increasing the chance of incorrect tool use, over-collection of context, or misuse of PPTX-manipulation workflows in situations where the user did not clearly request them.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
70% confidence
Finding

The file lists English and Chinese instruction and guide variants, but does not state how the user's preferred language is selected. Because language handling is documented without an explicit opt-in or choice mechanism, this can conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This appears to be a Chinese README, but key usage content and all trigger phrases are presented only in English. That can amount to an implicit language policy constraint because users are not offered a locale choice or told that English triggering is required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file contains multiple Chinese-language titles in the evidence section, but there is no note explaining any language or locale expectations for users or reviewers. Under the stated policy, language constraints or language-specific behavior should either offer user choice or be explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.