Back to skill

Security audit

Dazzle Photo Intelligence

Security checks across malware telemetry and agentic risk

Overview

This skill is a clearly disclosed OAuth bridge for querying the user's own Dazzle photo intelligence data, with privacy-sensitive but purpose-aligned behavior.

Install only if you are comfortable letting your local agent query Dazzle for sensitive information derived from your own photos, including places, relationships, routines, and preferences. Use narrow prompts when possible, and remove the MCP server or revoke the Dazzle grant if you no longer want silent follow-up access after sign-in.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation guidance is intentionally broad and encourages use for open-ended personalization tasks such as inferring relationships, preferences, location, and recent activities from photos. That increases the chance the assistant will over-collect or over-query highly sensitive photo-derived data when a narrower, less invasive response would suffice.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The description prominently advertises that the agent can infer where the user lives, who is in their life, and personal preferences from photos, but it does not include an explicit warning that these are highly sensitive inferences. Without a clear warning, users may not appreciate the privacy risk of exposing intimate behavioral, relational, and location data through ordinary queries.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.