Back to skill

Security audit

image-translate

Security checks across malware telemetry and agentic risk

Overview

This image translation skill is mostly coherent, but local images may be uploaded to a permanent public URL without requiring a clear runtime warning or deletion control.

Use this skill only for images you are comfortable sending to Flyelep and making reachable through a permanent public link. Avoid confidential, personal, regulated, or unreleased business images unless the provider gives you acceptable retention and deletion controls. Provide the API key only at runtime and do not store it in files or repositories.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill explicitly states that uploaded files become permanently accessible via a public, unsigned URL, but it does not require a clear user-facing warning or confirmation before upload. This can expose sensitive images, embedded personal data, trade secrets, or regulated content to unintended public access, especially because users may assume the upload is temporary or private.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.