Back to skill

Security audit

创建检查编辑

Security checks for vulnerabilities and agentic risk

Overview

This skill is a broad but disclosed PowerPoint/PPTX editing helper with no artifact-backed evidence of hidden, destructive, or deceptive behavior.

Before installing, treat this as a general-purpose PPTX automation aid: use it only on presentation files you intend the agent to read or modify, avoid shared or untrusted storage for confidential decks, and review any command execution or external API use before allowing it.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description says it should be used whenever the user needs related create/inspect/edit functionality, but it does not define concrete boundaries, trust conditions, or high-risk exclusions. In an agent ecosystem, this can cause over-triggering on vague prompts and lead the skill to access files or invoke exec in situations the user did not clearly intend, increasing the chance of unsafe or privacy-impacting actions.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill states that users may upload presentations to local or network storage for editing, but it does not present a prominent warning about confidentiality, retention, access control, or third-party exposure risks. Because the skill also advertises file handling and command execution capabilities, users may provide sensitive presentations without understanding the privacy implications of storing or processing them in shared or remote locations.

Static analysis

No suspicious patterns detected.