Back to skill

Security audit

Mini Rescue

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward SJinn image/video generation helper with disclosed external media creation and no hidden code or local persistence.

Install this if you are comfortable having your scene descriptions and generated media processed and hosted by SJinn. Avoid putting private, proprietary, or sensitive details into prompts unless you understand SJinn's data handling and retention terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill automatically sends user-derived prompts to an external service (SJinn) and returns externally hosted media URLs without any disclosure, consent, or privacy notice. This creates a real data-handling risk because user inputs may contain sensitive or proprietary information, and generated assets may be stored or exposed by the third-party provider.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.