gpt-multimodal

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward OpenAI image-analysis guide, but users should be mindful that selected images and visible text are sent to OpenAI when used.

Install only if you are comfortable sending chosen images, screenshots, frames, prompts, and any visible text in those images to OpenAI. Avoid using it on secrets, regulated records, private documents, or sensitive screenshots unless approved, and prefer a dedicated API key with usage limits.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill repeatedly instructs users to send local images and video frames to the OpenAI API, but it does not clearly disclose the privacy and data-governance implications of transmitting potentially sensitive visual content off-system. This can lead to unintentional exposure of PII, confidential documents, screenshots, location data, or regulated data because users are not prompted to classify or minimize sensitive content before upload.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal