Back to skill

Security audit

face swap

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed face-swap helper that uploads user-selected media to verging.ai and uses local media tools, with no hidden executable code or deceptive behavior found.

Install only if you are comfortable sending the selected video and face image to verging.ai and fetching any remote URLs you provide. Use a dedicated VERGING_API_KEY, avoid sensitive or unauthorized media, and clean up temporary files in /tmp/verging-faceswap/ after use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The README explicitly encourages use of remote video/image URLs and automatic downloading of results, but it does not warn users that their media and URLs may be transmitted to third-party services or that external content will be fetched locally. In a security-sensitive CLI context, this omission can lead to privacy exposure, unexpected network access, and unsafe handling of untrusted remote content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.