Image Scanner

Security checks across malware telemetry and agentic risk

Overview

This is a local image-folder reporting skill that reads filenames and metadata, with no evidence of network access, credential use, persistence, or implemented file-moving behavior.

Install only if you want a basic local photo-folder scanner. Run it on an explicit photo directory, avoid whole-home or sensitive folders, and treat the style/color classification claims cautiously because the current code mostly reports file metadata and guesses style from filenames.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are very broad and can activate the skill for generic requests about scanning, analyzing, or organizing photos without clearly stating scope, confirmation, or safety boundaries. In a skill that can enumerate directories and optionally move files, ambiguous activation increases the chance of unintended filesystem operations or overbroad processing of user data.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The markdown states that the skill may automatically create subfolders and move files, but it does not warn users about destructive or state-changing filesystem behavior. This is dangerous because users may invoke classification expecting analysis only, while the skill could reorganize originals, causing confusion, broken workflows, or unintended data loss if paths, duplicates, or rollback are not handled safely.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal