Douyin Cover Builder(抖音封面生成器)

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Douyin cover prompt skill with a reasonable photo-privacy caution but no evidence of hidden execution or data misuse.

Safe to install as a prompt-generation skill. Only upload portraits you have permission to use, avoid sensitive or third-party likenesses unless consent is clear, and review the image model provider's privacy and retention terms before using personal photos.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly encourages users to upload a personal photo to preserve a consistent face, but it provides no notice about how that image will be used, stored, shared, or retained. Because photos are sensitive personal data and may also be sent to downstream image-generation systems, this creates a real privacy risk through uninformed collection and potential third-party exposure.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal