Gamma Presentations Skill
Audited by Socket on Mar 10, 2026
1 alert found:
Obfuscated FileThe Gamma Presentations Skill demonstrates coherent purpose-capability alignment: it orchestrates content generation via Gamma API from local content and user prompts, with standard API-based authentication and export options. Data flows are predominantly source-to-Gamma API to results, with reasonable containment within a single service boundary. No evident suspicious or malicious usage patterns (e.g., unverifiable binaries, credential forwarding to unknown services, or autonomous real-world actions) are present. The main risk vector is user data exposure when sending workspace content to a third-party API; users should review Gamma’s data handling/privacy policies and apply data minimization when necessary. Overall, the footprint is BENIGN with MEDIUM-low security risk due to data-in-motion and potential privacy considerations. A cautious stance is warranted if highly sensitive documents are processed; otherwise, the design is proportionate to its stated purpose.