Back to skill

Security audit

YouMind Blog Cover

Security checks across malware telemetry and agentic risk

Overview

This skill mostly does what it says, but it asks for broader local command authority than needed and may activate on ambiguous image requests.

Review before installing. The YouMind API key, remote image generation, generated-image storage on a YouMind board, and global CLI install are expected for this skill. The main cautions are that ambiguous image requests may invoke it unexpectedly, and its local Node.js permissions should be narrowed or justified.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrase "thumbnail" is broad and commonly used for many image-generation or media-editing requests unrelated to blog headers. This can cause the skill to activate unexpectedly, leading users to send content to the YouMind service and execute external CLI actions when they intended a different tool or workflow.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The phrase "cover image" is ambiguous and can match requests for books, albums, social posts, presentations, or other non-blog contexts. In this skill, activation can lead to installation prompts, credential checks, and remote API usage, so overbroad matching increases the chance of unintended tool invocation and data disclosure to a third-party service.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger "featured image" is widely used across CMS, e-commerce, and social publishing contexts, not just blog covers. Because this skill performs external networked actions and may process URLs or user content automatically, accidental activation broadens the attack surface and can misroute user requests to an unintended third-party integration.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.