Back to skill

Security audit

PPTX Add Slides

Security checks across malware telemetry and agentic risk

Overview

This skill coherently edits user-provided PowerPoint files to create a new output deck, with no evidence of hidden network access, credential use, persistence, or destructive behavior.

Install only if you are comfortable letting the skill read a PPTX you provide and write a new PPTX to the output path you choose. Use a separate output filename if you want to avoid overwriting an existing file.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill clearly describes writing a modified PPTX to an output path, which is a file-write capability, yet no declared permissions are present. Undeclared write access is risky because callers or policy layers may not realize the skill can create or overwrite files, reducing transparency and weakening permission enforcement.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill metadata repeatedly describes the capability and use cases only in Chinese, which can steer the agent into responding in Chinese even when the user did not request that language. This is a real policy/UX safety issue because it can override user preference, reduce comprehension, and cause incorrect task execution for users expecting another language, though it is not a code-execution or data-exfiltration risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal