Ai Product Description Generator From Image

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: it sends a user-provided public product image URL to x.ai/Grok to generate product copy, without local persistence or hidden system changes.

Install only if you are comfortable using an x.ai API key and sending product image URLs to api.x.ai. Avoid signed, private, internal, or sensitive image links, and strip unnecessary tracking or access-token query parameters before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill processes user-supplied image URLs via an external AI provider, but the description does not clearly warn users that submitted URLs and associated content are sent off-platform. This can cause unintentional disclosure of sensitive product assets, tracking URLs, or proprietary content to a third party, especially if users assume analysis happens locally.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal