Back to skill

Security audit

Product to Ads (Ad-Ready)

Security checks across malware telemetry and agentic risk

Overview

This ad generator is not malware, but it needs review because it can preserve and analyze people's faces, bodies, ethnicity, and exact poses for commercial ad images without strong consent or rights safeguards.

Install only if you are comfortable sending product URLs and image assets to ComfyDeploy. Use public product pages and assets you have rights to use, and do not use real people, model photos, or reference ads for likeness or pose preservation unless you have clear consent and commercial usage rights.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill clearly instructs use of network access, environment variables, and writing files under /tmp, yet it declares no permissions. That mismatch undermines least-privilege controls and informed review because the agent may transmit data externally and manipulate local files without an explicit permission contract.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The prompt materially shifts the skill from product-focused ad generation into intimate, talent-centric scene construction, including suggestive framing, body-focused pose directives, and emotional/psychological staging. In a URL-driven advertising skill, this broadens output into potentially sexualized or manipulative human-image generation that is not clearly disclosed by the manifest, increasing misuse risk and policy/safety gaps.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The prompt requires exact preservation of a provided talent identity and exact replication of a pose reference, creating a strong resemblance-generation and image-copying mechanism not disclosed in the skill description. This increases the risk of non-consensual likeness use, face/identity misuse, and unauthorized mimicry of copyrighted or sensitive reference imagery.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The prompt explicitly instructs exact preservation of a real person's facial features, ethnicity, body type, and even exact pose replication from reference images. In an ad-generation skill, this enables identity-preserving likeness reproduction and targeted synthetic imagery, which can facilitate unauthorized commercial use, impersonation, or deceptive endorsements if the referenced person did not consent.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The prompt requires the model to infer and preserve sensitive traits such as ethnicity, age range, skin tone, and detailed body characteristics from a talent image. This goes beyond what is necessary for URL-driven product ad creation and increases privacy, profiling, and discrimination risk, especially in commercial targeting contexts.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The prompt is clearly designed for a different workflow ('MORFEO CREATIVE STAGE') focused on manual talent/image-directed creative generation, which conflicts with the skill’s declared URL-driven Ad-Ready behavior. This mismatch can cause the agent to request or depend on different inputs, generate outputs outside expected constraints, and mis-handle user data or business logic because the operational contract of the skill no longer matches its implementation.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The inline label identifies the file as 'MORFEO CREATIVE STAGE', directly contradicting the advertised Ad-Ready identity. In agent systems, identity mismatches are dangerous because they can route execution, operator expectations, and safety reviews around the wrong threat model, increasing the chance of unauthorized capabilities or incorrect handling of user requests.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
Defaulting generated ad copy to Spanish without explicit user opt-in can cause unintended output transformation and user-request mismatch. In a commercial workflow this may lead to incorrect public-facing content, brand risk, or accidental disclosure that the agent is making unstated assumptions about user preferences.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The API documentation repeats that Spanish is the default output language unless overridden, which bakes a silent behavioral assumption into downstream execution. This is risky because it can systematically produce wrong-language content in user-facing ads without clear consent or preview.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
Mandating that the system describe the talent's ethnicity exactly as visible forces demographic inference from appearance, a sensitive attribute classification that may be inaccurate, unnecessary for ad rendering, and harmful if embedded into generation logic. This creates bias, privacy, and discrimination risks, especially because the user is not told this attribute will be inferred or used.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The prompt begins with a broad imperative to analyze arbitrary injected inputs and generate output, but it does not define strong activation boundaries, trust tiers, or sanitization rules for untrusted fields such as PRODUCT_JSON, CAMPAIGN_BRIEF, KEYWORD_BANK, and CREATIVE_REFERENCES. In an agent skill that may receive attacker-controlled content from product URLs or user-supplied briefs, this increases prompt-injection risk because hostile instructions embedded in those fields can influence model behavior, output quality, or policy compliance.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The prompt instructs the model to preserve a person's ethnicity exactly from a reference image, which hard-codes a sensitive attribute into generation behavior without any user opt-in, necessity check, or policy guardrail. In an ad-creation skill, this can facilitate demographic targeting or exclusionary creative decisions based on protected characteristics, increasing fairness, compliance, and misuse risk.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
This second instruction repeats and strengthens the requirement to preserve ethnicity and skin tone exactly, reinforcing use of protected traits as immutable generation constraints. In the context of professional ad production, that makes the issue more concerning because the skill is explicitly designed for brand-aware, scalable creative output, which could operationalize sensitive-attribute-based ad generation across campaigns.

Vague Triggers

Medium
Confidence
92% confidence
Finding
This prompt file is effectively a broad, reusable system prompt but contains no explicit activation guardrails, user-intent checks, or scoping metadata to constrain when it should be applied. In an agent ecosystem, ambiguous invocation can cause the skill to be selected in unintended contexts, leading to inappropriate processing of arbitrary URLs, images, or brand/talent inputs and increasing the risk of prompt misuse or cross-context data handling errors.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The instruction hard-codes a specific cultural aesthetic ('Latin American magical realism') without user opt-in, which can steer outputs toward demographic or cultural framing the user did not request. In an advertising generation skill, this is risky because it may produce biased, culturally incongruent, or brand-inappropriate content at scale, especially when users expect neutral or brand-driven creative control.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.