AI 3D generation

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Neural4D API helper skill, with normal cloud-processing privacy and token-handling caveats.

Install only if you are comfortable sending selected prompts and images to Neural4D/DreamTech for processing. Keep NEURAL4D_API_TOKEN secret, avoid putting it in logs or shared files, and do not upload confidential, regulated, personal, or proprietary content unless your organization has approved the provider and its retention terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs users to send text prompts and images to an external third-party API, but it does not warn that potentially sensitive user content will leave the local environment or describe the privacy implications. This can lead users to unknowingly transmit proprietary designs, personal images, or confidential manufacturing data to Neural4D, creating avoidable privacy and compliance risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal