Back to skill

Security audit

pptx

Security checks for vulnerabilities and agentic risk

Overview

This PPTX skill is not clearly bounded to presentation work and asks agents to use broad command and API capabilities under a vague document-processing purpose.

Review before installing. Use only if you are comfortable with a PPTX-labeled skill that may guide the agent toward command execution, API credentials, and broad automation. Prefer a version that limits activation to explicit presentation tasks and requires confirmation before using credentials, network services, or shell commands.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is presented as PPTX/POTX handling, but its setup and recovery guidance expands into generic API access, command execution, and network troubleshooting. This scope mismatch is dangerous because it can normalize use of powerful capabilities under a narrow file-processing label, increasing the chance that an agent invokes external services or shell-like operations that users did not intend.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The advertised purpose is narrow—processing PPTX/POTX files—but the description broadens into generic development automation, workflow orchestration, GitHub-based validation, LLM API use, and command execution. That discrepancy undermines least privilege and informed consent, because a caller may authorize a document skill while actually enabling far broader actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Instructions to configure API keys and initialize API connections introduce credential handling and outbound network behavior that are not justified by a PPTX-processing skill. This creates risk of secret exposure, unintended data exfiltration, or unauthorized third-party processing of presentation contents.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documentation explicitly instructs users to execute commands, despite the skill being framed as a PPTX handler. Shell or command execution materially raises the attack surface because malicious or malformed inputs could be translated into system-level actions far beyond document parsing or generation.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger language says to use the skill any time a PPTX/POTX file is involved in any way, which is excessively broad. Overbroad activation is dangerous here because the skill also advertises powerful non-PPTX behaviors, making accidental invocation capable of exposing data, invoking APIs, or performing unintended actions in unrelated contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation condition states the skill triggers when users need 'related operations,' which is too vague to enforce clear boundaries. In the context of a skill already mixing document handling with APIs and command execution, ambiguity increases the likelihood of accidental overreach and misuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.