Back to skill

Security audit

Github Image Hosting

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward GitHub image-upload helper, but users should avoid uploading screenshots or mockups that contain sensitive information.

Install only if you are comfortable sending selected images to img402.dev and posting the resulting links in GitHub. Before using it on screenshots or mockups, check for tokens, private URLs, customer data, unreleased product details, or anything else that should not leave your local environment or repository context.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger language is broad enough to invoke this skill for generic requests involving screenshots or images, which can cause an agent to upload user-generated or sensitive visual content to an external service without explicit, situation-specific confirmation. In this skill’s context, that risk is amplified because screenshots often contain secrets, internal URLs, or personal data, and the skill promotes immediate upload workflows.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to upload images to img402.dev but does not clearly foreground that this is a third-party external hosting service, which can lead to unintended disclosure of sensitive data outside GitHub or the local environment. This is particularly dangerous for screenshots and mockups, which commonly contain confidential information, access tokens, customer data, or unreleased product details.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.