Gif Cog

Security checks across malware telemetry and agentic risk

Overview

This documentation-only skill coherently uses CellCog to generate GIFs and does not show hidden, destructive, or unrelated behavior.

Install only if you trust CellCog and the cellcog Python package. Avoid sending secrets, regulated data, private customer content, or proprietary media unless CellCog's policies and your organization allow it; use a revocable API key where possible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly requires a CellCog API key and directs users to send prompts and media-generation requests to an external service, but it does not clearly disclose that user prompts, files, and possibly generated outputs may leave the local environment and be processed by a third party. This creates a real privacy and data-handling risk, especially if users provide proprietary assets, internal product screenshots, or sensitive business content under the assumption the skill is purely local.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal