Back to skill

Security audit

Face

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed avatar-search helper that fetches synthetic face options from Generated Photos and keeps selection under user control.

Install this if you want an agent to fetch synthetic human-face avatar options from Generated Photos. Be aware it may make third-party web requests when avatar-like prompts match, and only approve saving a chosen face link in identity if you want it reused later.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is broad enough to match many ordinary avatar, profile, or group-image requests, which can cause the agent to invoke this skill in situations the user did not specifically intend. Because the skill performs external web fetching and image selection, overbroad activation increases the chance of unnecessary third-party requests and inappropriate routing of user tasks.

Vague Triggers

Low
Confidence
84% confidence
Finding
The purpose statement uses vague activation language across several contexts ('agent, persona, group, or Telegram surface'), making it easier for orchestration logic to select this skill for loosely related requests. In context, this is less severe than direct code execution, but it still creates a prompt-routing weakness that can lead to privacy-affecting external calls or user-confusing behavior.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.