Back to skill

Security audit

QuiverAI Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward QuiverAI SVG helper, but users should understand that prompts and images may be sent to an external AI service.

Install only if you trust the external QuiverAI CLI and service. Do not use it with confidential prompts, private URLs, proprietary designs, or sensitive images unless you are comfortable sending that material to QuiverAI. Choose output filenames deliberately to avoid overwriting existing SVG files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill encourages generating/vectorizing SVGs using QuiverAI models, including from image URLs, but does not warn that prompts, referenced files, or fetched remote images may be transmitted to an external third-party service. This creates a real data-exposure risk if users provide sensitive images, proprietary designs, or confidential prompts under the assumption processing is local.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.