MS Investment Deck

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a disclosed PowerPoint deck generator for investment presentations, with no evidence of hidden access, exfiltration, persistence, or unsafe account actions.

Install this only if you want help generating investment or finance-facing PPTX decks. Review all generated financial claims, ratings, targets, disclaimers, and any embedded local images before sharing with clients, investors, or internal committees.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description is broadly scoped to many common presentation requests, including generic investment decks, roadshows, memos, and quarterly updates. In an agent environment, this can cause over-triggering or routing hijack, where the skill is selected for requests that may be better handled by a narrower or user-confirmed tool, increasing the chance of unintended data handling or incorrect workflow execution.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The documentation shows a default language of Chinese (`language="zh"`) without indicating user consent or locale detection. In a multi-user agent setting, this can lead to outputs in an unexpected language, causing confusion, miscommunication, or accidental disclosure to the wrong audience when users assume the result will match their preferred language.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal