Back to skill

Security audit

创建检查编辑

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple PowerPoint/PPTX automation instruction file with broad but disclosed local read, write, and command capabilities, and no evidence of hidden persistence, exfiltration, or destructive behavior.

Install only if you are comfortable letting the agent read and modify presentation-related files and run local commands for PPTX work. Use it in a limited project folder and review generated decks or edited files before sharing them.

Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill declares powerful tools including read, write, and exec, and later mentions file handling and command execution, but the early description does not prominently warn users that local files may be modified and system commands may run. This can lead operators to invoke the skill with overly broad trust, increasing the chance of unintended file changes, unsafe command execution, or disclosure of sensitive local data.

Static analysis

No suspicious patterns detected.