Back to skill

Security audit

Google MediaPipe

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only MediaPipe reference skill with normal setup examples and no hidden execution behavior.

Safe to install as a reference skill. When using its examples, treat photos, video, audio, and text as potentially sensitive: get consent where needed, avoid unnecessary storage, use trusted model/package sources, and follow applicable privacy rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill prominently describes face, hand, pose, gesture, and language processing capabilities, which can involve biometric and other sensitive personal data, but it provides no privacy notice, consent guidance, retention limits, or misuse warnings. In a reusable agent skill, this omission can lead users to build or deploy surveillance-style or privacy-invasive workflows without understanding legal, ethical, and data-protection implications.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.