Back to skill

Security audit

飞影数字人 V2

Security checks across malware telemetry and agentic risk

Overview

This documentation-only skill is not executable malware, but it gives face and voice cloning guidance without adequate consent, biometric privacy, or retention safeguards.

Review before installing or using. Use this only for people whose face and voice you are authorized to clone, require clear consent and rights documentation, confirm the third-party platform’s retention/deletion terms, label synthetic media where appropriate, and do not rely on the skill’s broad compliance claim for companion, minor-facing, therapeutic, or emotionally interactive deployments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The compliance section claims the tool is outside emotional companionship scope, but the documented features explicitly include emotion recognition, soothing behavior, companion scenarios, and warm supportive responses. This mismatch can mislead deployers into using the skill in regulated or higher-risk interpersonal contexts without appropriate safeguards, policy checks, or user disclosures.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The avatar cloning workflow instructs users to upload a minute of video to create a custom likeness, but it omits any requirement to obtain the subject's consent or to verify rights to their image and biometric data. That omission creates a straightforward path to non-consensual impersonation, privacy violations, and misuse of facial/voice data.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The voice cloning section tells users to upload 5-10 minutes of clean audio for model training but provides no warning that voiceprints are sensitive biometric identifiers and can enable fraud, impersonation, or unauthorized synthesis. In a skill centered on producing expressive digital humans, this materially increases the risk of deceptive or abusive use.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.