Back to skill

Security audit

scene-replace

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent image background replacement helper, but uploaded local images become permanent public links and require a user-provided Flyelep API key.

Install only if you are comfortable using Flyelep's API with your own secretKey. Do not upload confidential, personal, or proprietary images unless you accept that the upload may produce a permanent public URL accessible to anyone with the link; prefer already-public image URLs for sensitive workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs users to upload local files and states the returned URL is permanent and unsigned, but it does not require any explicit warning or confirmation that the image will become publicly accessible. This creates a real privacy and data exposure risk, especially if users upload personal, confidential, or proprietary images assuming the upload is temporary or access-controlled.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.