Flux Image

Security checks across malware telemetry and agentic risk

Overview

This is a coherent FLUX image-generation helper, with expected external-service and CLI-install risks users should understand.

Install only if you trust inference.sh and are comfortable running its CLI installer. Prefer reviewing the installer or using the manual checksum path, and avoid sending confidential prompts, private image URLs, secrets, or sensitive images through this skill unless that is approved for your workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill encourages sending prompts and image URLs to an external service via the inference.sh CLI, but it does not prominently warn users that their text prompts and referenced images may be transmitted to a third-party system. In a skill that handles user-supplied creative content, this creates a real privacy and data-handling risk, especially if users provide sensitive images, internal designs, or confidential prompts.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal