Alvis AI PPT Generator

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed SkillBoss API Hub PowerPoint helper, but users should understand that prompts may be sent to that external service.

Install only if you are comfortable using SkillBoss API Hub for presentation generation. Avoid submitting secrets, regulated data, or confidential material unless that service is approved for it, use a dedicated API key if possible, and verify any referenced scripts before running them because they were not present in the reviewed package.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs the agent to send the user-provided PPT topic to the external SkillBoss API Hub, but the description does not clearly warn users that their content leaves the local environment. This creates a privacy and data-handling risk because users may include sensitive business, personal, or confidential material in prompts without informed consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal