LH HTML to Image

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward guide for turning local HTML and CSS into an image with Chrome, with no hidden code, persistence, credentials, or account access.

Install if you are comfortable with your agent using a local Chrome or Chromium command to render an HTML file and create an image. Use trusted HTML files, choose output paths deliberately to avoid overwrites, and do not set CHROME_PATH to an unknown executable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad enough to match common user requests such as 'poster' or 'make image', which can cause the skill to activate unexpectedly outside its intended scope. Over-broad activation increases the chance of the agent selecting this skill for unrelated tasks and invoking local HTML/Chrome-based rendering behavior when a user did not explicitly request it.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal