PPT Pandora

Security checks across malware telemetry and agentic risk

Overview

This is a PPT-making guide with a visible optional Feishu file-send example, not a hidden uploader or automatic data-access tool.

Safe to install as an instruction-only PPT workflow. Before running any Feishu send command, confirm the exact file path, recipient, channel, and account, especially when the presentation contains private or client material.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
The skill includes Feishu file transmission commands, which extend beyond local PPT generation into outbound data transfer. In an agent context, any built-in messaging capability can be abused to exfiltrate generated presentations or embedded source material to external recipients, especially if recipient IDs or file paths are supplied without strict validation and user confirmation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal