Tmp.Qh1hHlhweP

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Gemini image-generation MCP setup guide, with expected API-key use and local image output behavior.

Before installing, treat @chrischall/gemini-mcp as third-party code with access to your GEMINI_API_KEY. Use a limited API key where possible, remember that image generation may bill your Google Cloud project, and set output_dir or GEMINI_OUTPUT_DIR deliberately if generated or edited images may be private. Use inline mode or clean up saved files when you do not want image outputs left on disk.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
91% confidence
Finding
The skill documents that images are saved to disk via returned file paths and notes that the current working directory is used by default, but it does not clearly warn users that generated and edited images persist on local storage unless `inline: true` is used. This can lead to accidental storage of sensitive or private image content in unexpected locations, especially when users assume outputs are ephemeral.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal