Back to skill

Security audit

seo-images

Security checks across malware telemetry and agentic risk

Overview

This skill provides coherent image SEO auditing and optimization guidance, with file changes disclosed as part of the requested optimization workflow.

Installers should understand that the audit portions are read-oriented, while the optimize workflow can create new image files or change metadata in existing images. Before running optimization commands, confirm the target path, keep originals or backups, and avoid injecting copyright, creator, or AI-source metadata unless it is accurate.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill includes file-modifying operations such as metadata injection, format conversion, compression, and variant generation, but it does not present a clear upfront warning that these actions can alter user files and metadata. In an agent context, this increases the risk of unintended destructive changes, privacy-impacting metadata edits, or overwriting assets when a user expects read-only analysis.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.