Back to skill

Security audit

PPT快速生成器

Security checks across malware telemetry and agentic risk

Overview

The skill appears coherent and clean, with the main caution being an external commercial link users should evaluate separately.

Before installing, treat the linked external site as third-party: review its domain, privacy terms, pricing, and data practices before entering sensitive content or purchasing. The clean VirusTotal result and low advisory signal do not show malware or unsafe automatic behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
89% confidence
Finding
The skill description explicitly directs users to an external website for the 'full version' and commercial licensing without any notice that they are leaving the platform or that any data entered there may be subject to separate privacy and security practices. This creates a phishing, tracking, and data-handling risk because users may trust the linked site as platform-endorsed and may disclose sensitive business or presentation content there.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.