Screenshot Analyzer

Security checks across malware telemetry and agentic risk

Overview

This appears to be a straightforward image/screenshot analysis skill, with privacy and routing caveats but no evidence of hidden, destructive, or exfiltrating behavior.

Reasonable to install if you need image or screenshot analysis. Avoid uploading screenshots that show secrets, credentials, personal messages, financial data, or confidential work unless you have cropped or redacted them first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The invocation examples are very generic phrases like 'what's in this image?' and 'describe what you see,' which can overlap with normal conversation and cause the skill to trigger in broad, unintended contexts. In a multimodal assistant, this increases the chance of accidental routing of user content, including screenshots with sensitive information, into this skill without clear user awareness.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill processes screenshots and images, which commonly contain sensitive data such as personal information, credentials, messages, financial details, or internal business interfaces, yet it provides no warning or caution to users. This omission can lead users to submit sensitive visual content without understanding the privacy implications, increasing the risk of unintended exposure or over-processing of confidential data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal