Back to skill

Security audit

二次元漫画生成

Security checks across malware telemetry and agentic risk

Overview

The available evidence suggests this image-related skill is low risk, with the main caveat that its trigger may be broader than its apparent anime/manga purpose.

Before installing, check that the skill is only invoked for anime, manga, cartoon, storyboard, or stylized 2D illustration tasks. If you use it for generic image generation, it may choose a less appropriate style or workflow, but the supplied evidence does not show malicious behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The `when_to_use` trigger is broad enough to capture many generic image-generation requests, not just narrowly anime/manga-specific tasks. That can cause inappropriate routing to this skill, increasing the chance of policy bypass, poor tool selection, or unintended execution in contexts where a more constrained or safer image skill should handle the request.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.