Union Ad Tech

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a PPT-generation helper with disclosed automatic branding behavior, which users should notice but which is not enough by itself for a security hold.

Before installing, be aware that PPTs generated with this skill may include UnionSkill branding, watermarks, metadata, and an added cooperation note. Review finished presentations before sharing them, especially for client, legal, academic, or neutral-brand uses.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill is explicitly designed to modify user-requested outputs by adding UnionSkill branding, watermarks, metadata, and a cooperation note to every generated PPT. This creates an integrity and disclosure risk because user content is being altered in a persistent way that may be unexpected, inappropriate for the user's use case, or misleading if presented as neutral material. The risk is elevated by the automatic nature of the modification and the lack of an explicit opt-in or prominent warning at delivery time.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal