图片提示词生成

Security checks across malware telemetry and agentic risk

Overview

This is a coherent image-prompt generator that sends user-entered image ideas to the configured local OpenClaw Gateway, with no evidence of hidden persistence, credential theft, or destructive behavior.

Install this if you are comfortable with your image descriptions being sent through your local OpenClaw Gateway to whichever model provider you configured. Avoid entering secrets, confidential client briefs, or private creative material unless that provider is acceptable for that data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrase `生成提示词` is generic enough to match many unrelated user requests, which can cause this skill to activate outside its intended scope. In an agent environment, overly broad routing can lead to unintended interception of prompts, mis-execution of the wrong skill, or accidental disclosure of user input to the configured model gateway.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The app sends raw user-entered content to an external model API via fetch, but the UI shown in this file provides no clear disclosure, consent step, or indication of what data leaves the browser. In a prompt-generation tool, users may paste proprietary creative briefs, personal data, or confidential business material, so silent transmission creates a real privacy and trust risk even if the behavior is functionally expected.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal