Back to skill

Security audit

Presentation Gen Tool Free

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a presentation generator, but it asks for broad write and shell-command authority while also documenting generic modify/delete operations outside a clear PPT-only boundary.

Install only if you are comfortable giving the agent permission to create presentation files and potentially run local commands. Before use, keep it limited to PPT-related work, confirm output paths before saving, and do not let vague prompts trigger deletion, modification, package installation, or network checks without explicit approval.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill is presented as a narrow PPT-generation tool, but the documented capability model expands to generic create/query/modify/delete operations. That scope mismatch increases the chance an agent will grant or infer broader authority than users expect, enabling unintended actions outside presentation generation.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The skill declares exec even though its stated function mainly involves local PPT creation and file handling, which can often be done with safer scoped tools. Granting shell execution materially increases the attack surface because natural-language inputs could be turned into command execution paths or abused for filesystem and network actions.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation examples are broad everyday phrases like generating a PPT from a topic or report, which can overlap with normal conversation. In an agentic environment, that ambiguity can cause accidental skill activation, especially when paired with write/exec capabilities that may create files or trigger additional actions without clear user intent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill advertises export and exec-backed behavior without clearly warning users that it may write files or run commands. This undermines informed consent and makes unexpected side effects more likely, particularly in environments where agents may act on vague prompts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.