Back to skill

Security audit

Image Gen

Security checks across malware telemetry and agentic risk

Overview

This is a coherent AI image-generation skill that sends confirmed prompts to Labnana and saves generated images locally, with privacy and trigger-scope caveats users should understand.

Install only if you are comfortable providing a ListenHub/Labnana API key and sending image prompts plus any reference image URLs to that provider. Avoid sensitive prompts or private/tokenized image links, and review the confirmation summary before approving generation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger "visualize" is similarly broad and can refer to explanation, planning, or conceptual reasoning rather than image generation. In this skill, accidental activation matters because the workflow ultimately sends prompts and optional URLs to a third-party service.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger "visualize" is similarly broad and can refer to explanation, planning, or conceptual reasoning rather than image generation. In this skill, accidental activation matters because the workflow ultimately sends prompts and optional URLs to a third-party service.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Repeating broad trigger examples in the usage section reinforces permissive invocation behavior and makes accidental matching more likely across the platform. Because this skill performs external transmission and file creation, loose activation criteria increase security and privacy risk beyond simple UX issues.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The guide instructs authors to always convert prompts to English before submission, removing user language choice and creating an undisclosed transformation step. While not a classic exploit, this can misrepresent user intent, introduce translation errors, and create fairness/accessibility issues for non-English users, especially when culturally specific wording matters.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.