Back to skill

Security audit

tripo3d

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Tripo3D API helper, but users should understand that prompts, images, and an API key are used with an external service.

Install only if you trust Tripo3D and are comfortable sending generation prompts or selected images to that service. Store the API key as an environment variable, do not paste it into chat or saved scripts, avoid uploading sensitive personal or proprietary images, and review any PowerShell proxy/download command before running it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs users to upload local images or provide image URLs to a third-party API, but it does not explicitly warn that user-provided images will be transmitted off-platform and may contain sensitive personal or proprietary data. This creates a real privacy and consent risk, especially for photos of people, private spaces, or confidential materials.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The skill requires a sensitive API key in an environment variable but provides no guidance on secure handling, storage, or avoiding accidental disclosure in prompts, logs, or code snippets. While this is not an exploit by itself, it increases the chance of credential leakage or misuse during operation.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.