Back to skill

Security audit

Cn Ppt Outline

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a presentation-making helper with minor disclosure and naming issues, but no evidence of hidden access or harmful behavior.

Before installing, check that you are comfortable with the skill creating or exporting presentation files and ignore or verify the unrelated AISoBrand promotional link separately. The publisher should remove the off-topic promotion, use clear ASCII identifiers, and document expected permissions, but the current evidence does not justify a Review or malicious label.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding
Without declared permissions the skill's intent is opaque and cannot be validated.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Description-Behavior Mismatch

Low
Confidence
92% confidence
Finding
The manifest describes a skill for generating PPT outlines and exporting PowerPoint files, but the closing section advertises AISoBrand and links to a free brand-exposure diagnosis service. This is not an implementation detail of PPT generation and expands the documented behavior into unrelated promotional functionality.

Static analysis

No suspicious patterns detected.