Back to skill

Security audit

ImageRouter

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only ImageRouter skill whose network calls, API key use, and selected image uploads fit its stated image-generation purpose.

Install only if you are comfortable sending your prompts, selected images, masks, and API-key-authenticated requests to ImageRouter. Avoid private, regulated, or proprietary content unless you accept the provider's handling of that data, and review generated download URLs and output paths before saving files locally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The documentation explicitly instructs users to upload local image files and text prompts to a third-party API, but it does not warn that these inputs leave the local environment and may contain sensitive data. In an agent skill context, this omission can cause unintentional exfiltration of private images, masks, prompts, or derived metadata to an external service.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.