Back to skill

Security audit

Comic Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward CellCog comic-generation helper with expected external API use and no hidden local persistence or destructive behavior.

Install this only if you are comfortable sending your comic prompts, character descriptions, and any referenced task content to CellCog. Avoid including secrets, private business material, regulated personal data, or confidential unpublished work unless you have reviewed and accepted CellCog's data handling terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs users to send prompts to CellCog via an external API but does not clearly disclose that prompts, attached files, or other task content may leave the local environment and be processed by a third-party service. This can cause inadvertent disclosure of sensitive source code, business data, personal information, or confidential creative material, especially because the examples normalize direct prompt submission without any privacy warning.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.