Back to skill

Security audit

MiniMax Vision Analysis

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed MiniMax image-analysis helper, but users should be careful about what images or image paths they let it process.

Install only if you are comfortable configuring MiniMax MCP and sending chosen images or image references to MiniMax for processing. Protect the API key, verify the external MCP package before setup, and avoid analyzing confidential screenshots, documents, private URLs, or local paths unless you intend to share them with that service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill auto-triggers on any message containing common image file extensions, even when the user is only mentioning a filename or URL rather than asking to analyze an actual image. That can cause unintended routing to the vision tool, increasing the chance of unnecessary external data disclosure or confusing execution based on incidental text.

Vague Triggers

Medium
Confidence
91% confidence
Finding
Many trigger phrases such as 'describe', 'explain', 'review', or 'tell me about' are extremely common and not specific enough to image-analysis intent on their own. In a skill that forwards content to an external vision service, ambiguous triggers increase the risk of accidental invocation and unintended transmission of user-supplied paths, URLs, or related content.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The workflow says the skill triggers automatically when a message contains an image path or URL with certain extensions, but it does not distinguish between actual attached images and mere textual references. This ambiguity is dangerous because it can cause the agent to process unintended content or send externally hosted/local image references to a third-party service without sufficiently clear user intent.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs use of the MiniMax external MCP service but does not clearly warn users that image files, URLs, and extracted text may be transmitted to a third party for processing. In a vision/OCR context, this can expose sensitive screenshots, documents, personal photos, or embedded secrets without informed consent, making the context more dangerous rather than less.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.