Back to skill

Security audit

PPT-Matcher

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent PPT style-analysis helper, with normal file-reading behavior and disclosed slide-editing guidance, but users should back up presentations and install dependencies carefully.

Before using it on an important deck, work on a copy and confirm exact slide numbers before any page is deleted or recreated. Install python-pptx in a virtual environment from a trusted package index, ideally with pinned versions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:68
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs an agent to delete the old slide and recreate a new one in place, but it does not require confirmation, backup creation, or a user-visible warning that the operation is destructive. In an automated agent workflow, this raises the risk of accidental data loss or irreversible corruption of the presentation if the redesign is wrong, the wrong slide is targeted, or execution partially fails.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description and invocation guidance are presented only in Chinese, which effectively forces a specific language for users without opt-in. The file does not state that the skill is intended only for a Chinese-speaking or region-specific environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

SQP-3 applies to all file types and includes language/locale policy violations. The module docstring and command-line usage strings present the tool exclusively in Chinese, with no opt-in or alternative language support, which can violate a policy requiring language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script prints operational status and sampling information only in Chinese. Because no language preference is requested or configurable, this is a natural-language policy concern under SQP-3 rather than a code-security issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The usage/help text shown on incorrect invocation is only in Chinese, again imposing a single language without opt-in. This matches the SQP-3 language policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.