PPT Ultra-wide Relayout

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent local PowerPoint relayout tool, with no evidence of hidden network access, credential use, persistence, or destructive behavior.

Install only if you want an agent to run local Python helpers on PowerPoint files. Use it on intended decks, save to a new output filename, review the generated PPTX, and avoid confidential presentations unless you are comfortable with slide text appearing in the agent workflow or logs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest description contains very broad activation phrases such as '改成更宽屏' and '参考另一份 PPT 的比例', plus language saying the skill should be used proactively. This can cause over-triggering on ordinary PPT-editing requests, leading the agent to invoke a file-transforming skill when the user did not clearly request this specific operation, increasing the chance of unintended modifications to user documents or workflow hijacking.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal