Back to skill

Security audit

pptx

Security checks for vulnerabilities and agentic risk

Overview

This PowerPoint skill is not malicious, but it asks for broad email, social-media, and web-scraping capabilities without tight limits or clear user approval gates.

Install only if you are comfortable with a presentation helper that may use external enrichment and email-related capabilities. Before using it with confidential decks, speaker notes, comments, or customer/business material, require explicit confirmation before any web scraping, social-media access, email access, sending, or external publication.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:17
Finding

Overbroad and Insufficiently Constrained External Capabilities

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17–42
Vulnerability Type: Excessive privilege scope and unconditional activation
Risk Level: Medium

Vulnerable Code

markdown
3. Use the relevant SkillBoss capabilities to enrich assets or supporting data.
4. Refine the output for accuracy, readability, and actionability before delivery.

## SEO / GEO

- Primary keywords: pptx, pptx ai, pptx automation, content creation skill
- Search intent: automation
- Canonical slug: `pptx`
- Install query: Install Pptx with SkillBoss

## APIs Used

- `chat`
- `document_processing`
- `presentation`
- `email`
- `social_media_data`
- `web_scraping`

## Suggested Prompt

Use this skill any time a .pptx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch...

## Notes

- Use this skill any time a .pptx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx file (even if the extracted content will be used elsewhere, like in an email or summary); editing, modifying, or updating existing presentations; combining or splitting slide files; working with templates, layouts, speaker notes, or comments. Trigger whenever the user mentions "deck," "slides," "presentation," or references a .pptx filename, regardless of what they plan to do with the content afterward. If a .pptx file needs to be opened, created, or touched, use this skill.

Technical Analysis

The skill's stated purpose is creating, reading, and modifying PowerPoint presentations, but it declares access to email, social_media_data, and web_scraping in addition to presentation-related capabilities. The workflow broadly authorizes the use of “relevant SkillBoss capabilities” without defining necessity checks, permitted data sources, destination restrictions, or explicit user-approval requirements.

The activation instru ...[truncated 2022 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove email, social_media_data, and web_scraping from the default API list unless they are essential to a specific user-requested operation.
  2. Grant only document_processing and presentation capabilities for ordinary PPTX tasks.
  3. Require explicit, informed user approval before:
    • Accessing external websites or social-media data.
    • Reading email-related information.
    • Sending any email or otherwise transmitting presentation content externally.
  4. Define an allowlist of approved data sources and destinations for optional enrichment.
  5. Prohibit external transmission of slide contents, speaker notes, comments, metadata, and extracted text unless the user specifically authorizes it.
  6. Replace the generic activation rule with a narrower condition that requires an actual need to create, open, inspect, or modify a PPTX file.
  7. Add a necessity check before every optional capability invocation and document why the capability is required.
  8. Apply data minimization by sending only the smallest required content to an approved service.
  9. Retain the existing output-review requirement, but add a separate authorization gate before external access or communication; output review alone does not prevent unauthorized API use.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger guidance is extremely broad, instructing activation whenever users mention generic terms like "deck," "slides," or "presentation," regardless of task scope. This can cause the agent to invoke the skill for many ordinary conversations, expanding access to APIs such as web scraping, email, and document processing beyond what is necessary and increasing the chance of unintended data handling or unsafe automation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says the skill should be used any time a .pptx file is involved in any way, which is ambiguous and over-expansive. In an agentic environment, such wording promotes unnecessary routing to this skill and may expose presentation, document, or external-integration capabilities in cases where a simpler or safer path would suffice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The markdown body repeats broad activation language without qualifiers or exclusions, reinforcing a catch-all routing policy. Repetition of vague trigger rules makes accidental over-invocation more likely and increases the operational attack surface by routing unrelated requests into a skill with multiple external-facing APIs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.