Vintage Poster Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward remote image generator, but users should avoid sensitive prompts and protect their API token.

Install only if you are comfortable sending image prompts and a Neta API token to the Neta/TalesofAI service. Do not include secrets, personal data, or confidential business content in prompts, and prefer safer token handling where possible instead of pasting tokens directly into commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding
The skill advertises Bash execution and an external API workflow, but does not declare permissions despite static analysis detecting network capability. This creates a transparency and consent gap: users and host systems may not realize the skill can send data externally, increasing the risk of unintended prompt or token exposure.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill asks users for a Neta API token and instructs them to pass free-form prompts to an external image-generation service, but provides no warning that prompts and possibly related metadata will leave the local environment. Users may unknowingly submit sensitive or proprietary text, and token-handling via command line can also expose secrets through shell history or process inspection.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal