Back to skill

Security audit

icon-designer-generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a remote image-generation wrapper that sends design prompts and optional images to an external API, with no hidden install, persistence, or unrelated behavior found.

Install only if you are comfortable sending prompts, uploaded/reference images, design configuration, and generated outputs to the documented third-party services. Avoid submitting secrets, private business material, personal data, or confidential images unless your organization has approved that service and its data handling.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs users to send prompts, uploaded images, and detailed design configuration to a third-party remote API, but provides no privacy notice, retention policy, or warning that sensitive user content leaves the local environment. In an agent ecosystem, this can lead to unintentional disclosure of confidential text, proprietary images, or personal data, especially because users may assume a skill is local or trusted by default.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.