Back to skill

Security audit

commercial-image-prompt

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent commercial image-prompting guide with platform-specific templates and no unusual access, persistence, or hidden behavior.

Install this if you want help writing commercial image-generation prompts. Expect platform-specific output, including Chinese templates for Chinese platforms; review generated prompts for brand accuracy and do not include confidential product details unless they are appropriate for the image prompt.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
This JSON eval includes a prompt and expected constraints entirely in Chinese for a Xiaohongshu-oriented output, which imposes a specific language/locale in the skill behavior being tested. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern unless clearly justified as a region-specific tool.

Natural-Language Policy Violations

Low
Confidence
85% confidence
Finding
This JSON file contains natural-language evaluation text that expects the skill to handle a Chinese-language Xiaohongshu prompt and produce Chinese-structured output requirements. Because the file does not indicate that this locale-specific behavior is optional, user-selected, or limited to a region-specific use case, it may reflect an undocumented language/locale constraint.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.