Back to skill

Security audit

pptx

Security checks across malware telemetry and agentic risk

Overview

This skill gives straightforward PowerPoint creation, editing, analysis, and QA guidance, with no hidden persistence, credential use, or unrelated data handling.

Install this if you want agent help with PowerPoint files. Be aware it may activate for broad slide or presentation-design prompts, so only let it inspect or modify files you intentionally provide for that task.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description uses very broad activation language such as 'PPT, slides, presentations' and 'create, modify .pptx files,' which can match many ordinary conversations that do not require file operations or this specific skill. Over-broad routing increases the chance the agent invokes the skill inappropriately, causing unnecessary access to local presentation files or execution of helper tooling in contexts the user did not intend.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The 'When to Use This Skill' section includes ambiguous cues like 'mentions slides, PPT, or presentations' and 'asks for help with presentation design,' which lack clear boundaries between general advice and operations on PowerPoint files. This can lead to unnecessary or premature skill activation, expanding the attack surface by routing unrelated user prompts into a tool-capable skill that may inspect or modify files.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.