Back to skill

Security audit

PPT 中文工具基础版

Security checks across malware telemetry and agentic risk

Overview

The skill is a Chinese PowerPoint helper, but it mixes local-only privacy claims with external API/network use and broad command-capable instructions, so it should be reviewed before installation.

Install only if you are comfortable with an agent that may read local presentation files, run local commands, use API keys, and contact external APIs. Treat the local-only privacy statement as unreliable unless the publisher clarifies which actions are fully local and which send content over the network.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The documentation states that all data is stored locally and implies privacy safety, but nearby sections also state that some features require network access and rely on external APIs. This can mislead users into providing sensitive presentation content under a false assumption that no data will leave the machine, creating a real confidentiality and consent risk.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger condition says to use the skill for broad data analysis, report generation, statistical insight, and visualization, which is far outside the stated PPT-focused scope. Overbroad triggering can cause an agent to invoke this skill in unrelated contexts where exec or network-capable behavior may run with inappropriate user expectations, increasing the chance of unsafe command execution or unintended data handling.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation example is extremely generic and could match many unrelated user requests, making accidental skill activation more likely. In an exec-enabled skill, vague invocation increases the risk that the agent applies the skill to the wrong task and performs actions the user did not specifically intend.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill declares MD+EXEC capability but does not provide a prominent warning that it may execute shell commands. Users may assume they are only invoking a formatting/document assistant, while the agent may actually run commands on the host, which materially changes the trust and risk model.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill notes that some features require network connectivity and external APIs, but it does not prominently warn users that their content or metadata may be transmitted externally. This creates a data handling transparency issue and can expose sensitive document contents without informed consent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.