Back to skill

Security audit

Alt Text Generator AI

Security checks across malware telemetry and agentic risk

Overview

This skill is a narrowly scoped connector for generating image alt text through OOMOL, with no hidden files or unrelated behavior found.

Install only if you intend to use OOMOL's connector for Alt Text Generator AI. Be aware that image URLs and request data will be sent through the OOMOL-connected service, and review the CLI installer before running first-time setup commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The description instructs the agent to use this skill for ANY request involving Alt Text Generator AI and instead of calling the API directly, which is an overly broad trigger that can cause the skill to be invoked for incidental mentions of the service rather than clear user intent. This increases the chance of unintended external calls, unnecessary data exposure to the connector, and incorrect tool-routing behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.