Back to skill

Security audit

Visual Dna

Security checks across malware telemetry and agentic risk

Overview

This is a coherent text-only design-analysis skill, but users should avoid giving it private or unauthorized references.

Install only if you are comfortable with an agent analyzing the references you provide. Do not supply private screenshots, internal URLs, authenticated pages, regulated data, or third-party designs unless you have permission; review generated Design DNA before committing or sharing it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README explicitly states that the skill will analyze user-supplied URLs or project assets and 'does not try to judge ownership, sensitivity, or permission to analyze a reference.' In an agent setting, that can normalize processing third-party or sensitive internal resources without a privacy gate, increasing the chance of unauthorized analysis or exposure of confidential visual/material assets.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs the agent to fetch and analyze user-supplied URLs or project assets, while also saying not to judge ownership, sensitivity, or permission. That creates a real privacy and network-safety risk: the agent may access third-party or internal resources, leak request metadata, or process sensitive content without consent or clear disclosure.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The instruction to fetch real assets from original URLs during generation encourages unsolicited external requests and embeds remote dependencies into generated output. This can expose user activity to third parties, create tracking/privacy issues, and produce fragile or policy-violating artifacts that depend on unvetted remote content.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.