Back to skill

Security audit

PPT 工具 v1.0 基础版

Security checks across malware telemetry and agentic risk

Overview

This PowerPoint skill is not clearly malicious, but its requested command and network capabilities are broader and less clearly scoped than its documentation suggests.

Install only if you are comfortable giving the agent command execution and local presentation-file access for PPT work. Avoid using it with confidential presentations or API keys unless you first confirm whether processing stays local and when external APIs, callbacks, or network access are used.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill makes conflicting trust and data-handling claims: it states FREE edition data is stored locally and not uploaded to the cloud, while elsewhere declaring that some features require network access and external API usage. This can mislead users into exposing document contents, metadata, or credentials to remote services under a false expectation of local-only processing.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger conditions are overly broad and drift beyond the stated PPT-focused domain, increasing the chance that an agent invokes this skill for unrelated tasks. In a skill with exec and possible network/API use, unintended invocation can lead to unnecessary command execution, file access, or data disclosure outside user expectations.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The natural-language invocation guidance is too vague, telling users the agent will automatically execute matching operations without clear boundaries or confirmations. This raises the risk of the agent selecting this exec-capable skill on ambiguous prompts and performing unintended actions on local files or remote services.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill advertises broad document-processing functionality but does not prominently warn that it uses exec-capable command execution and may access external APIs or the network. Users may provide sensitive presentations, templates, or credentials without understanding that local commands may run and content may leave the host environment.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.