Back to skill

Security audit

Avatar Creation

Security checks across malware telemetry and agentic risk

Overview

The skill is coherent for CellCog avatar creation, but it handles sensitive voice and likeness data with insufficient consent, privacy, and retention guidance.

Install only if you are comfortable sending avatar prompts, images, and voice samples to CellCog for persistent account-level reuse. Do not upload or clone a person's voice or likeness unless you own it or have clear permission, and confirm CellCog's retention and deletion controls before using sensitive media.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The manifest description is extremely broad and promotional, covering avatar creation, voice cloning, image generation, personalities, and persistent reuse across chats without clear activation boundaries. In systems that auto-route or suggest skills from descriptions, this can cause over-invocation for loosely related user requests and unexpectedly expose users to a remote third-party service handling sensitive media and persona data.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill instructs users to upload audio for voice cloning but provides no consent, authorization, or privacy warning. Voice data is highly sensitive biometric information, and cloning a person's voice without explicit permission can enable impersonation, fraud, and serious privacy harm, especially because the skill presents the workflow as frictionless and immediately usable.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill states that avatars are persistent and visible across all CellCog chats, but it does not clearly warn users that uploaded images, voices, and persona data remain account-level assets available in future contexts. This increases the risk of inadvertent cross-chat data exposure, unexpected reuse of sensitive likeness or voice material, and user misunderstanding about how long personal data remains accessible.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.