IceCube Digital Human

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only guide for creating AI digital humans, with sensitive likeness and voice privacy risks but no hidden code or automatic access.

Install only if you intend to use voice and avatar cloning. Use your own likeness or material with documented consent, review each provider's privacy, retention, deletion, and reuse terms before uploading samples, and clearly label generated videos as AI-created before publishing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to upload voice samples, photos, and videos to third-party cloning services, but it does not prominently warn that these are sensitive biometric identifiers that may be retained, reused, or exposed by external providers. In the context of voice/avatar cloning, this omission is especially risky because the data can enable impersonation, fraud, and irreversible privacy harm if mishandled.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The workflow describes generating and outputting digital-human videos to specified platforms without clearly warning that publication may expose a user's cloned identity, likeness, and synthesized speech to the public. In a digital-human skill, this materially increases risk because automated distribution can amplify reputational harm, consent violations, and misuse before the user understands the consequences.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal