Back to skill

Security audit

Nano Triple

Security checks across malware telemetry and agentic risk

Overview

This appears to be a purpose-aligned image-generation skill, but users should review its prompt-to-shell handling before use.

Install only if you intend the agent to generate images from your prompts. Invoke it explicitly, avoid feeding untrusted prompt text into shell commands, and inspect the SKILL.md command examples to ensure prompt values are passed as safely quoted arguments rather than interpolated into a raw shell string.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are very generic and likely to match ordinary user requests unrelated to a deliberate invocation of this skill. That increases the chance of unintended activation, causing the agent to launch image-generation workflows unexpectedly, consume resources, and potentially route user content into external tooling without clear consent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.