Translate Image

Security checks across malware telemetry and agentic risk

Overview

This is a coherent image translation and OCR skill that uses a disclosed third-party API, with privacy and rights-use cautions users should understand.

Install only if you are comfortable uploading chosen images to translateimage.io using a TranslateImage API key. Avoid sensitive screenshots, documents, IDs, secrets, personal photos, or regulated data unless the provider's privacy and retention practices are acceptable. Use text removal only for images you own or have permission to modify, especially where watermarks, attribution, subtitles, or evidentiary annotations are involved.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly sends user-provided images to a third-party service (`translateimage.io`) but does not clearly warn users that their image contents will leave the local environment. This creates a real privacy and data-sharing risk, especially if users submit sensitive screenshots, IDs, documents, or personal photos under the assumption processing is local.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The text-removal feature is described as suitable for removing overlays, watermarks, and subtitles without warning that this may alter evidence, violate rights, or facilitate circumvention of ownership markings. Because the output is intentionally destructive and can remove provenance-related content, the omission of caution is a meaningful safety issue.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal