Back to skill

Security audit

PowerPoint PPTX Layout Export

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only PowerPoint helper that gives proportionate guidance for generating, repairing, and exporting PPTX files, with no hidden execution, persistence, credential handling, or exfiltration behavior found.

Install only if you want Codex to help inspect or edit PowerPoint decks. For important or sensitive presentations, review any generated code or edited PPTX before use and keep the original deck, as the skill itself recommends.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger sentence is extremely broad and unnatural, matching generic requests like 'Help me' and 'I need a practical workflow' with a long appended requirement fragment. Overbroad activation criteria can cause the skill to fire in unrelated contexts, leading an agent to apply PowerPoint-specific automation or assumptions when the user did not clearly request this capability.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger sentences are generic enough that the skill may activate on loosely related user text rather than an explicit request to use this PowerPoint helper. In an agent system, overbroad activation can cause unintended invocation, misrouting, or tool use in contexts where the user did not intend PPTX processing, increasing the chance of unsafe file handling or unintended actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are generic and loosely scoped, which can cause the skill to activate for unrelated requests that merely mention PowerPoint or workflows. In an agent environment, over-broad activation increases the chance of unintended file manipulation, misleading automation, or invocation in contexts where the skill is not appropriate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

文件名 SKILL.zh-CN.md 及全文内容表明该技能以简体中文(中国)形式提供,但文档没有说明这是可选语言,也没有为用户提供语言切换或选择机制。根据规则,未经过用户选择就强制特定语言/地区属于自然语言政策问题。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

技能描述中的触发条件覆盖面较宽,包含大量泛化需求表述,容易在并非专门处理 PowerPoint/PPTX 自动化的场景下被误触发。误触发本身不是代码执行漏洞,但会造成错误技能介入、越权式上下文扩张或对用户意图的错误路由,在代理系统中可演变为安全边界弱化。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

关键词列表包含较常见且语义可扩散的词项,如与创意内容或办公场景相关的通用表达,缺少足够上下文限定时可能导致技能在无关对话中被激活。在多技能代理环境中,这类歧义触发会增加错误工具选择、信息暴露面扩大和结果偏离用户真实需求的风险。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill enables allow_implicit_invocation without any visible trigger constraints or narrowing conditions, so the agent may auto-select this capability in broader contexts than intended. Because this skill can modify, repair, and export PowerPoint content, ambiguous activation increases the chance of unintended document processing, data exposure through file handling, or misuse in prompt-injection-driven workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger scope is ambiguous because it relies on keyword-style descriptions and incomplete phrases rather than well-bounded conditions for when the skill should run. In an agent environment, ambiguous routing can misinvoke the skill on adjacent document, automation, or presentation requests, increasing the chance of incorrect actions, unnecessary file handling, or unsafe transformations of user content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
69% confidence
Finding

The file presents user-facing instructions primarily in Chinese and does not state that language selection is optional or limited to a specific audience. For user-facing skill materials, forcing a specific language without opt-in can violate language or locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.