Back to skill

Security audit

Potaco

Security checks across malware telemetry and agentic risk

Overview

Potaco is a coherent image-generation skill that uses disclosed provider APIs and credential handling, with no artifact-backed evidence of hidden or unsafe behavior.

Before installing, understand that Potaco sends prompts and, for edits, source images and masks to the configured image provider. Use only providers and custom base URLs you trust, prefer interactive credential setup, avoid passing API keys in shell flags or environment variables unless necessary, and review debug output before sharing it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documentation explicitly describes image editing workflows that send source images and masks to external providers, but it does not warn users that potentially sensitive image content may leave the local environment. In a tool that supports third-party providers and custom OpenAI-compatible endpoints, omission of a privacy/data-transmission warning can lead users to unknowingly upload confidential or personal imagery.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.