Back to skill

Security audit

Image Scene Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a product-image prompt generator with no hidden access, credential use, or unsafe install behavior found.

Install this if you want help creating AI image prompts for product listings or marketing visuals. Be aware it may activate on broad product-photo requests, and if you run the optional batch script, choose input and output paths deliberately because it will overwrite the specified output file.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger description is extremely broad and includes generic requests like 'better photos,' 'more angles,' and product-related visual improvement asks, which can cause the skill to activate outside its intended scope. Over-broad invocation increases the chance of inappropriate routing, unexpected handling of user inputs, and accidental access to attached product images or business context when another skill would be more appropriate.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The fallback trigger examples such as 'make this look premium' and 'I need images for my listing' are ambiguous and can match many unrelated tasks, including conventional photography advice, marketplace optimization, or general marketing help. This ambiguity makes the skill more likely to be invoked unexpectedly, creating routing confusion and increasing exposure of user-supplied assets or commercial information to an unnecessary workflow.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.