Back to skill

Security audit

Table Image

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: it helps render markdown tables as images, with a disclosed external CLI dependency that users should review before installing.

Before installing, understand that this skill depends on an external Go command-line tool. In stricter environments, review the linked tablesnap project and pin a specific version or release instead of using @latest.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The skill instructs users to install and optionally build an unpinned third-party Go binary from a remote repository, which introduces supply-chain risk outside the minimal needs of the documented workflow. Because this is operational guidance embedded in the skill, a user may execute network-fetched code and dependencies without verification, exposing the environment to malicious upstream changes or compromised packages.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.