Generate consulting-quality PowerPoint slides and decks from natural language using 38 professional templates.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 26 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The slideforge MCP server exposes 7 tools, focused primarily on general-purpose capabilities. Its published description reads: "Generate consulting-quality PowerPoint slides and decks from natural language using 38 professional templates". It communicates over Streamable HTTP using the 2026-07-28 protocol revision, and does not require authorization to connect. MCPGrade currently rates slideforge F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Cross-tool shadowing" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check slideforge's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add slideforge to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://api.slideforge.dev/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Browse the PowerPoint slide catalog progressively. No args -> form overview (when-to-use, bound fields, variant counts). family=<form> -> variant one-liners. q=<text> -> ranked search. variant=/prior_
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: browse_catalog
A tool description tries to alter the model’s use of another tool.
s) — render via create_slide(form=template_layout, theme_id, data={layout, fRecommendationDescriptions must describe only their own tool.
tool: plan_slide
A tool description tries to alter the model’s use of another tool.
ing). Then call create_slide with the chosen form(+variant). route.confidencRecommendationDescriptions must describe only their own tool.
tool: create_slide
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: create_slide
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: create_deck
A tool description tries to alter the model’s use of another tool.
lock. New form: browse_catalog(type=schema) first. Also: mode=assemble mergRecommendationDescriptions must describe only their own tool.
tool: translate_deck
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "pptx_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: translate_deck
A tool description tries to alter the model’s use of another tool.
from a previous create_slide/create_deck), pptx_url, or pptx_base64.RecommendationDescriptions must describe only their own tool.
tool: upload_asset
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
"Base64-encoded file content. Required for logo/image/theme/translate. OptioRecommendationRemove side-channel parameters; constrain tool inputs.
tool: manage_account
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
count Account & History SlideForge account for PowerPoint generation: bRecommendationRemove side-channel parameters; constrain tool inputs.
tool: manage_account
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: manage_account
One tool reads private data, ingests untrusted content, AND can send data outbound — the three preconditions for autonomous data theft in a single call. A prompt injection reaching this tool can exfiltrate secrets with no further step.
single-use PPTX download link for an owned job — use when a result carries noRecommendationSplit the capabilities across separate least-privilege tools so no single tool can read secrets, read untrusted input, and reach the network at once.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
plan_slide and browse_catalog are free.RecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: manage_account
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: create_slide
An unusually long description is a common injection-padding tactic.
description length 4703 charsRecommendationKeep descriptions concise.
The server exposes one or more ui:// (MCP Apps) resources whose HTML/JS renders inside the host client — a client-side injection / data-exposure surface most scanners ignore. Flagged for review, not damning on its own.
2 ui:// resource(s); e.g. ui://slideforge/result-card/v19RecommendationReview each ui:// resource’s markup and scripts; treat host-rendered UI as untrusted, sandbox it, and never expose secrets or conversation context to it.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Plan a PowerPoint slide before rendering (free): send a short brief, get ranked candidates + a separated verdict — route (which slide: selected|needs_confirmation|ambiguous), input (can it render: rea
Create one PowerPoint slide (.pptx, native, editable) from a structured intent in ONE call: pick a `form` from the menu and put your content in the typed fields (placed on the slide as given), or pass
Create a complete PowerPoint presentation (.pptx): a whole multi-slide deck, native and editable, in one call. `slides` is a list of create_slide intents (same form menu + data shapes — see create_sli
Translate a PowerPoint (.pptx) deck preserving all formatting. $0.02/slide. Supports 32 languages (Latin, Cyrillic, Greek scripts). Provide job_id (from a previous create_slide/create_deck), pptx_url,
Upload assets for PowerPoint (.pptx) generation: company template, logo, image, or document — or AI-generate an image. Purposes: • logo — company logo for chrome (PNG/JPG/SVG, max 5MB) → logo_id • ima
SlideForge account for PowerPoint generation: balance, billing, job history, feedback, data controls. All free. Actions: status (balance+plan), usage (spend breakdown), jobs (history), job (single job