Back to skill

Security audit

Pptx Notes Editor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent PowerPoint speaker-notes helper that reads and edits user-selected PPTX files with explicit confirmation before modifications.

Install this if you want an agent to help inspect and edit PowerPoint speaker notes. Use it only on presentations you are comfortable letting your agent read, and review the generated note drafts before approving any PPTX modifications.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The README tells users to "Simply describe what you want to do" and gives examples like "Help me edit the speaker notes...", which are natural conversational phrases rather than narrowly scoped invocation triggers. Without clearer trigger boundaries or exclusion conditions, this increases the risk of unintended activation in agent environments that infer skill use from free-form text.

Static analysis

No suspicious patterns detected.