Back to skill

Security audit

my skill

Security checks across malware telemetry and agentic risk

Overview

This is a simple presentation-design instruction skill with no code, installs, credentials, file access, or network behavior.

This skill is reasonable to install for drafting or designing slide content. Review generated content before using it, and remember that any separate tool used to convert the markdown into an actual .pptx may have its own permissions or data-handling risks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description is broad enough to trigger on many generic presentation-related requests without clear boundaries. Overly broad invocation criteria can cause the wrong skill to activate, leading to unintended handling of user requests and increasing the chance of context mixing or inappropriate tool usage.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The catch-all trigger 'Any request involving PowerPoint, slides, or presentation creation' lacks scope limits and can match a wide range of loosely related requests. This increases the risk of over-invocation, where the skill may intercept requests better handled by other skills or general reasoning, reducing reliability and potentially exposing downstream systems to unnecessary actions.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.