Back to skill

Security audit

Ai Image Gen Pro

Security checks across malware telemetry and agentic risk

Overview

This is a coherent instruction-only image-generation skill for the inference.sh CLI, with normal privacy and cost cautions for remote AI image services.

Before installing, confirm you trust the inference.sh CLI and its install source, understand where infsh login stores credentials, and avoid submitting confidential prompts, private images, or sensitive URLs unless you intend to send them to the remote model provider. Also check pricing before running paid image models.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list is unusually broad and includes many generic phrases such as 'image generation', 'generate image', 'ai art', and 'generative ai', which increases the chance the skill is invoked in contexts where the user did not specifically intend to use this external CLI-backed capability. Because the skill can drive networked image-generation tools, unintended invocation can lead to unexpected remote requests, billing, or disclosure of user prompts to third-party services.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs users to run image-generation and image-processing commands through a remote service and includes examples that submit prompts and image URLs to external apps, but it does not clearly warn that prompts, images, and referenced URLs may be transmitted to third-party providers. In this context, users may unknowingly send sensitive text or private images off-platform, creating privacy, compliance, and cost exposure.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.