Back to skill

Security audit

Ntriq X402 Alt Text Batch

Security checks across malware telemetry and agentic risk

Overview

This is a simple paid alt-text API skill, with the main caution that image URLs and context are sent to the provider for processing.

Install or use this only if you are comfortable paying $3 USDC per batch and sending the selected image URLs plus any provided context to x402.ntriq.co.kr. Do not submit private, signed, internal, personal, or confidential image URLs unless that sharing is approved.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs users to send image URLs to a third-party remote endpoint but does not disclose the privacy and data-sharing implications. Even if only URLs are sent, those URLs may contain sensitive information, internal hostnames, signed access tokens, customer identifiers, or links to non-public assets, and the service operator will learn what resources the user is processing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal