Ppt Ocr

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward PowerPoint OCR helper that uses the MinerU command-line tool and token, with the main caveat that submitted slide content may be processed by an external service.

Install only if you are comfortable using MinerU for OCR. Treat files and URLs submitted through mineru-open-api as potentially sent to an external service, avoid confidential slide decks unless that service is approved for your use, and protect MINERU_TOKEN like any other API credential.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs users to process local files and remote URLs through `mineru-open-api`, which requires a token and therefore strongly implies content is transmitted to an external MinerU service. Because the skill does not warn users that presentation contents may leave the local environment, users may unknowingly upload sensitive slide data, creating a confidentiality and compliance risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal