Back to skill

Security audit

创建检查编辑

Security checks for vulnerabilities and agentic risk

Overview

This is a broad, template-like PowerPoint/PPTX helper skill, but its requested read/write/exec access is disclosed and generally aligned with editing presentation files.

Install only if you want an agent to help with local PPTX files. Give it specific file paths and task boundaries, review changes before sharing presentations, and do not provide API keys or sensitive presentation content unless they are necessary for the task.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description says to use it whenever the user needs related create/inspect/edit functionality, without clear trigger boundaries or exclusions beyond a vague statement about complex needs. In an agent environment with read/exec/write tools, this broad activation can cause the skill to be invoked for loosely related requests, increasing the chance of unnecessary file access, command execution, or unsafe automation in contexts the skill was not designed for.

Static analysis

No suspicious patterns detected.