Back to skill

Security audit

Morzai Skills

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed remote e-commerce image-processing suite, but users should know their product images may be sent to Morzai/Lumo services.

Install only if you are comfortable sending product images, reference images, image URLs, and listing context to the listed Morzai/Lumo remote services or through the morzai CLI. Avoid unreleased designs, confidential supplier assets, or sensitive credentials unless you have reviewed and trust the provider’s data handling.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This command sends user-supplied images or image URLs to an external remote MCP endpoint, but the manifest does not document any user-facing notice, consent step, or data-handling constraint. That creates a real privacy and data-governance risk because users may reasonably assume local processing while their content is transmitted to a third party.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The garment-retouch workflow accepts user images and routes them to an external service without any visible warning in the manifest. Because image inputs may contain sensitive commercial or personal information, undisclosed third-party transmission is a legitimate security and privacy concern.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This workflow similarly transmits user-provided images to a remote MCP URL with no documented user warning or consent mechanism. In an image-editing context, silent exfiltration to a third-party processor is a real vulnerability because it can violate privacy expectations and organizational data-handling requirements.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.