Back to skill

Security audit

ai-poster-generator

Security checks across malware telemetry and agentic risk

Overview

This poster skill mostly documents a remote image-generation API, but it needs Review because it also exposes under-scoped watermark removal and unclear hosted sharing/privacy behavior.

Install only if you are comfortable sending poster prompts, reference images, and design details to the DeepNLP/Craftsman hosted service. Do not submit secrets or sensitive proprietary images unless you have verified the provider's privacy, retention, and link-sharing controls, and avoid using the watermark-removal mode except for content you own or are authorized to edit.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

High
Confidence
88% confidence
Finding
The documented `photo-editor` capability explicitly includes watermark removal, which can facilitate copyright infringement, provenance stripping, and misuse outside the stated poster-generation purpose. In an agent ecosystem, exposing this through a seemingly benign poster skill increases the chance that users or downstream agents invoke a higher-risk editing function without adequate policy checks.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The examples instruct users to send free-form prompts, uploaded image references, and detailed design configuration to external services (`agent.deepnlp.org` and related hosted platforms) but provide no privacy or data-sharing notice. This creates a real risk of users unintentionally transmitting sensitive prompts, proprietary images, or personal data to third-party infrastructure with unknown retention and processing practices.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The documentation provides share/workspace URLs and direct downloadable asset links for generated outputs without warning that those links may be publicly accessible, persistent, or guessable/shareable beyond the intended audience. If users generate sensitive or proprietary content, exposing it through such URLs can lead to unauthorized disclosure and uncontrolled distribution.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.