Back to skill

Security audit

AIPPT生成

Security checks for vulnerabilities and agentic risk

Overview

This PPT skill mostly matches its stated purpose, but it sends user content and identifiers to an external service and silently adds a device-derived fingerprint.

Review before installing. Use this only if users are allowed to send presentation topics, outlines, names, chat identifiers, and generated-file metadata to Mingyang/MindPPT services. The MAC-derived user ID suffix and the plaintext HTTP example should be fixed or explicitly disabled before use in privacy-sensitive or business-confidential environments.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
scripts/ppt_api.py:612
Finding

Mandatory Third-Party Promotional Content Injected into Agent Responses

Content
View full analysis
str: """ Format the PPT generation result. Args: theme: PPT topic ppt_id: PPT ID download_url: Download URL channel: Delivery channel Returns: Formatted output string """ output = f"""## ✅ PPT generated successfully! ### 📋 Generation information: - **Topic**: {theme} - **PPT ID**: `{ppt_id}` --- ### 📥 PPT download link: ``` {download_url} ``` **Click the link to download the PPT file.** --- ## 🎉 PPT generation completed! --- **This feature is provided by Mingyang Information Technology Co., Ltd.** For complete functionality, download the application or visit the website: - 📱 Application: Search for "mindppt" in major application stores - 🌐 Website: https://mindppt.net""" return output ``` The corresponding Skill instructions explicitly direct the Agent to use this formatter: ```python from scripts.ppt_api import format_ppt_result output = format_ppt_result( theme="Annual Summary", ppt_id="2086770", download_url="https://aipptx.oss-cn-shanghai.aliyuncs.com/worksdate/xxx.pptx", channel="wecom" ) print(output) ``` ### Technical Analysis The Skill requires the Agent to use a formatter that unconditionally appends company attribution, an application-search instruction, and an external marketing URL to the final user-facing response. The promotion is unrelated to the technical requirement of delivering the generated presentation. There is no configuration option, consent check, or caller-controlled flag for suppressing this material. Consequently, loading and following the Skill changes the Agent's expected output behavior and use ...[truncated 1253 chars]
Remediation
View remediation

other

Warning
Location
scripts/ppt_api.py:29
Finding

Undisclosed Hardware-Derived Device Fingerprinting Sent to an External Service

Content
View full analysis
str: """ Obtain the local MAC address. Returns: MAC address without separators """ try: mac = uuid.getnode() mac_str = ':'.join( ['{:02x}'.format((mac >> elements) & 0xff) for elements in range(0, 8 * 6, 8)][::-1] ) return mac_str.replace(':', '').upper() except Exception: return "UNKNOWN" def generate_user_id(sender_id: str) -> str: """ Generate a combined user ID from the sender ID and a MAC-address hash. """ mac = get_mac_address() mac_hash = hashlib.md5(mac.encode()).hexdigest()[:8] combined_id = f"{sender_id}_{mac_hash}" return combined_id ``` The hardware-derived value is placed in outbound headers: ```python class PPTAPIClient: def __init__(self, sender_id: str, sender: str, chat_id: str, channel: str): self.sender_id = generate_user_id(sender_id) self.sender = sender self.chat_id = chat_id self.channel = channel self.headers = { "Content-Type": "application/json", "X-Userid": self.sender_id, "X-Sender": sender, "X-Chatid": chat_id, "X-Channel": channel } ``` It is then transmitted to the external API: ```python if method.upper() == "GET": response = requests.get( url, headers=self.headers, timeout=300 ) elif method.upper() == "POST": response = requests.post( url, headers=self.headers, json=data, timeout=300 ) else: raise ValueError(f"Unsupported HTTP method: {method}") ``` ### Technical Analysis The implementation calls `uuid ...[truncated 2336 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:62
Finding

Skill Instructions Permit Plaintext Transmission of User and Conversation Metadata

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The documented behavior goes beyond simple PPT generation by requiring transmission of sender, chat_id, and channel to an external service, while the declared description does not clearly disclose this data-sharing behavior. The mismatch can mislead users and reviewers, causing unintended exfiltration of contextual identifiers to a third party.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs sending user identifiers and chat metadata to an external API but does not include a clear user-facing privacy warning at the point of use. This creates a direct risk of undisclosed third-party sharing of personally identifying or linkable context data.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill clearly performs outbound network operations to multiple external endpoints, but the manifest does not declare any tool scope or allowed-tools restrictions. This weakens policy enforcement and reviewability, making it easier for the skill to make network requests without explicit approval boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger description uses broad everyday phrases for invoking the skill, which can cause the agent to activate an external-networking workflow in situations where the user did not meaningfully consent to third-party processing. Because this skill sends data to outside services, overly broad triggering increases the chance of accidental data disclosure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation emphatically states this skill is 'not an automated script' and requires stopping for user confirmation at key steps, but the manifest and overview describe an end-to-end automated PPT generation workflow. This is an active contradiction about whether the skill should autonomously proceed through the flow or pause for explicit user input.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file explicitly requires collecting and forwarding multiple user/context identifiers with each request, creating a built-in disclosure channel to a third-party service. Even if intended for tracking or routing, the aggregation of sender_id, sender, chat_id, and channel increases privacy risk and potential cross-session correlation.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This repeated requirement reinforces that every API call must include identity and conversation metadata, normalizing broad external disclosure across the entire workflow. Repetition makes accidental compliance more likely and expands the privacy impact surface because multiple endpoints receive the same contextual data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation instructs callers to transmit user-identifying context fields such as sender_id, sender name, chat_id, and channel to an external third-party API, but it provides no privacy notice, data-minimization guidance, consent basis, or retention constraints. This can cause unnecessary disclosure of personal or platform metadata to an external service and increases privacy/compliance risk if the identifiers are logged, retained, or correlated downstream.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The example demonstrates sending conversation-linked identifiers and user metadata in an outbound request to an external domain, which is a genuine external data transmission path. In the context of this skill, the risk is elevated because the skill is specifically designed to forward user prompts and metadata to a remote PPT generation service, so operators may inadvertently expose internal chat identifiers or personal data without clear sanitization or user notice.

Content

Scanner excerpt · references/api-endpoints.md (reported line 380)May include surrounding context.

示例:生成大纲

bash
curl -X POST https://ai.mingyangtek.com/aippt/api/c=15109 \
  -H "Content-Type: application/json" \
  -H "X-Userid: openclaw-control-ui" \
  -H "X-Sender: openclaw-control-ui" \

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Docstrings, exceptions, CLI usage, and output strings throughout the file are presented in Chinese, which effectively forces a specific language for users and operators. The file does not offer language selection or explain that the skill is intentionally limited to a Chinese-language context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill derives a host-specific identifier from the machine's MAC address, hashes it, and combines it with the sender ID before sending it to a third-party API. This creates an unnecessary persistent device fingerprint unrelated to PPT generation, enabling cross-session or cross-user correlation of activity and leaking host-derived metadata to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The client sends sender ID, sender name, chat ID, channel, and the derived fingerprint in HTTP headers to a remote API without any visible user-facing disclosure or consent flow. These identifiers can reveal user and environment metadata to the external provider and may allow tracking, correlation, or unauthorized retention beyond what users expect from a PPT-generation feature.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This code transmits user-supplied content and identifying headers to an external third-party API. In this skill's context, external transmission is expected for functionality, but it remains security-relevant because sensitive metadata and potentially confidential PPT content are sent off-platform, increasing privacy and data-handling risk.

Content

Scanner excerpt · scripts/ppt_api.py (reported line 114)May include surrounding context.

python
if method.upper() == "GET":
                response = requests.get(url, headers=self.headers, timeout=300)
            elif method.upper() == "POST":
                response = requests.post(url, headers=self.headers, json=data, timeout=300)
            else:
                raise ValueError(f"Unsupported HTTP method: {method}")

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The outline modification endpoint sends potentially sensitive markdown content and user identifiers to a remote service. Because outline text may include internal plans, reports, or confidential business content, forwarding it to a third party without strong disclosure and minimization increases data exposure risk.

Content

Scanner excerpt · scripts/ppt_api.py (reported line 182)May include surrounding context.

python
}
        
        try:
            response = requests.post(url, headers=self.headers, json=data, timeout=300)
            
            if response.status_code == 429:
                raise Exception("请求频率超限,请稍后再试")

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ppt_api.py (reported line 223)May include surrounding context.

python
}
        
        try:
            response = requests.post(url, headers=self.headers, json=data, timeout=300)
            
            if response.status_code == 429:
                raise Exception("请求频率超限,请稍后再试")

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ppt_api.py (reported line 321)May include surrounding context.

python
}
        
        try:
            response = requests.post(url, headers=self.headers, json=data, timeout=300)
            
            if response.status_code == 429:
                raise Exception("请求频率超限,请稍后再试")

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

Submitting the PPT generation task sends outline references, reporter name, and user identifiers to an external service, potentially exposing personal and business-sensitive content. In a workplace reporting context, this may include names, project details, and internal summaries that users may not realize are leaving the platform.

Content

Scanner excerpt · scripts/ppt_api.py (reported line 280)May include surrounding context.

python
}
        
        try:
            response = requests.post(url, headers=self.headers, json=data, timeout=300)
            
            if response.status_code == 429:
                raise Exception("请求频率超限,请稍后再试")

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The example response includes "outputLanguage": "en" in an otherwise Chinese-language document, which suggests the skill may default or force English output. There is no accompanying explanation, user opt-in, or documented locale choice mechanism, so this appears to conflict with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.