Back to skill

Security audit

Gamma Presentations

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it tells users to store and read a Gamma API key from a plaintext agent-readable file, which creates an avoidable credential exposure risk.

Install only if you are comfortable sending selected content to Gamma's API. Do not put the Gamma API key in TOOLS.md or any project document; use an environment variable or secret manager, and rotate any key that was already stored in plaintext.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:10
Finding

Plaintext API Key Storage in Agent-Readable Documentation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
## Setup

1. Get API key from https://developers.gamma.app
2. Store in environment: `export GAMMA_API_KEY=sk-gamma-xxx`
   Or add to TOOLS.md: `Gamma API Key: sk-gamma-xxx`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly suggests placing the Gamma API key in TOOLS.md, a plaintext documentation file that may be read, indexed, or exposed during normal agent operation. This creates an avoidable credential exposure risk because secrets stored in local prompt-accessible files can leak to users, logs, or other tools.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Advising operators to store the API key in a plaintext documentation file is a real secret-handling flaw in an agent skill context. Because agent systems often inspect local files as working context, the key could be unintentionally surfaced to the model, exfiltrated in outputs, or captured in logs and version control.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

Generate Content

bash
curl -X POST https://public-api.gamma.app/v1.0/generations \
  -H "Content-Type: application/json" \
  -H "X-API-KEY: $GAMMA_API_KEY" \
  -d '{

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Line L73 hard-codes a specific language in the natural-language example payload. This can violate language/locale policy when presented as the default behavior without telling users they can choose another language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.