Ai Product Photography

Security checks across malware telemetry and agentic risk

Overview

This is a coherent product-image generation skill that visibly relies on the inference.sh CLI and service, with install and privacy cautions but no hidden or malicious behavior in the artifact.

Install only if you trust inference.sh and are comfortable logging in through its CLI. Prefer the manual checksum-verification path for the CLI, use an account with appropriate spending limits, and avoid submitting unreleased products, private image URLs, customer data, or confidential marketing assets unless your organization has approved that service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill repeatedly instructs users to send prompts and, in the post-processing workflow, image URLs to a remote third-party inference service, but it does not clearly warn about privacy, retention, or data handling. In a product-photography context, prompts and images may contain unreleased products, branding, packaging, or other commercially sensitive assets, so lack of disclosure can lead to unintended data exposure.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal