Back to skill

Security audit

极简海报

Security checks across malware telemetry and agentic risk

Overview

This skill is a focused image-prompt helper that uses ImageGen for poster creation and does not show hidden persistence, credential access, or destructive behavior.

Install this if you want an opinionated minimal zine-poster generator. Be aware that ambiguous poster requests may route into this style, ImageGen may consume credits, and any reference photo you provide would be passed to the image-generation tool.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation description is broad enough to trigger on generic creative inputs like themes, moods, article ideas, photos, or content briefs, which can cause the skill to activate outside its narrow zine-poster niche. Over-broad routing is dangerous because it can hijack unrelated requests, force unnecessary tool usage, and bypass more appropriate specialized skills or normal assistant behavior.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The output format mandates Chinese labels ('生成图', '最终 Prompt', '说明') without checking the user's language or documenting a valid locale requirement. This can degrade usability, mislead users about the system's language behavior, and create avoidable prompt/output mismatches in multilingual contexts.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad, generic creative terms such as 'minimal poster' and 'editorial poster' that can match many ordinary user requests beyond this narrowly scoped skill. In an agent environment, this can cause unintended auto-invocation, routing user content into image-generation workflows the user did not explicitly request, which is a scope and consent problem rather than code execution.

Natural-Language Policy Violations

Low
Confidence
72% confidence
Finding
The description hard-codes a specific Japanese/Korean aesthetic as the default output without signaling that this is optional or user-selectable. In practice this can override user intent, introduce cultural-styling assumptions, and produce mismatched or potentially insensitive outputs, though the security impact is limited compared with execution or data-exfiltration issues.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.