Deckrun Pdf Generator Free

Security checks across malware telemetry and agentic risk

Overview

This skill transparently sends slide Markdown to an external service to create a public PDF link, so the main risk is accidental sharing of sensitive deck content.

Use this only for content you are comfortable sending to an external service and making available through a public PDF link for 90 days. Do not submit secrets, personal data, regulated information, or confidential business material through the free public endpoint.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill sends user-provided Markdown to a third-party service and returns a publicly accessible URL valid for 90 days, but it does not clearly warn users about this data exposure at the point of use. This creates a real confidentiality and privacy risk because agents may upload sensitive internal content, believing the operation is local or private, when the resulting document is published to an external storage location.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal