Back to skill

Security audit

Memorable Image Generator

Security checks across malware telemetry and agentic risk

Overview

This appears to be a disclosed Gemini image-generation skill that uses an API key, network calls, and local image files for its stated purpose.

Install only if you are comfortable providing a Gemini-compatible API key and sending prompts or input images to the configured API endpoint. Prefer reviewed install commands, keep the API key scoped where possible, and set the output directory somewhere you expect generated images to be saved.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill documentation indicates access to environment variables, local file read/write, and outbound network use, but it does not declare permissions explicitly. That creates a transparency and policy-enforcement gap: users or hosting frameworks may invoke the skill without understanding that it can read secrets, write files, and contact external services.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger language includes a broad catch-all condition such as 'any image generation request where memorability is a goal,' which can cause over-activation outside the user's specific intent. Overly broad activation increases the chance that this skill is selected in contexts where users did not consent to iterative API usage, file output, or memorability-oriented prompt modification.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.