Back to skill

Security audit

PPT字体修复工具(免费版)

Security checks across malware telemetry and agentic risk

Overview

This is a document-processing skill whose file and command access fit its stated PPT font repair and PDF conversion purpose, with some scoping cautions but no evidence of hidden or malicious behavior.

Before installing, expect the agent to read PPT files, write repaired or converted outputs, and possibly run local tools such as Python libraries or LibreOffice. Give explicit file paths, keep backups of important presentations, and avoid using callback URLs unless you trust the destination.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill uses broad natural-language triggers such as requests to fix fonts or convert PPT to PDF without strong scoping or confirmation requirements. In a skill that advertises read/exec/write capabilities, ambiguous activation can cause the agent to perform file operations or invoke local tooling on unintended inputs, increasing the risk of accidental modification or command execution.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill description presents document processing functionality but does not warn users that operation may modify files and may rely on command execution via local tools such as LibreOffice or Python-based processing. In this context, missing warnings are dangerous because users may invoke the skill without understanding that it can write outputs, alter documents, or execute system-level tooling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.