Back to skill

Security audit

PPTX Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward PowerPoint generation and editing helper, with disclosed local file changes and basic safeguards around destructive edits.

Install this if you want an agent to create and modify PowerPoint files. Before edits, make sure the target deck and output filename are clear, and ask the agent to write edited decks to a new file unless you intentionally want an in-place change.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough that normal user requests like 'edit this slide' or 'change text' could invoke this skill in situations where the user's intent is underspecified. Because the skill performs destructive file operations, ambiguous activation increases the chance of unintended edits or overwriting an existing deck, especially when combined with in-place modification behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.