Back to skill

Security audit

elite-ppt-pro

Security checks across malware telemetry and agentic risk

Overview

This skill is a presentation-generation guide with research and citation requirements, and I found no hidden persistence, credential use, destructive behavior, or unrelated data access.

Before installing, understand that this skill may prompt the agent to research external sources and create local PPTX/HTML deliverables. Review generated citations and file outputs, especially for confidential business topics.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger list includes broad phrases such as 'investor deck' and 'strategy deck' that can appear in ordinary user requests, increasing the chance of unintended activation. In an agent environment, accidental invocation can route user content into this skill unexpectedly, causing confusing behavior, over-collection of data, or execution of file-generation workflows the user did not explicitly request.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.