skills/ceeon/aippt-enterprise/aippt/Gen Agent Trust Hub

aippt

Fail

Audited by Gen Agent Trust Hub on Feb 23, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [CREDENTIALS_UNSAFE] (HIGH): The files 05_图床上传方法.md and tips/image-upload.md contain a hardcoded API key for the freeimage.host service (key=6d207e02198a847aa98d0a2a901485a5). Hardcoding credentials in skill documentation or scripts is a high-risk practice.
  • [DATA_EXFILTRATION] (MEDIUM): The core workflow requires uploading local PPT screenshots to third-party public image hosting services (e.g., freeimage.host, catbox.moe, litterbox) to obtain URLs for AI processing. This may result in the exposure of sensitive presentation content to external parties.
  • [COMMAND_EXECUTION] (MEDIUM): The skill documentation (01_导出方法.md) includes instructions for executing arbitrary AppleScript (osascript) and PowerShell code to automate Keynote and PowerPoint, which could be exploited to run unintended system commands.
  • [EXTERNAL_DOWNLOADS] (LOW): The skill utilizes npm install for the pptxgenjs library and makes network requests to external APIs such as api.apicore.ai and ismaque.org for image generation.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 23, 2026, 04:27 AM