Didit Face Search

Security checks across malware telemetry and agentic risk

Overview

This skill does what it advertises: it sends user-selected face images to Didit for duplicate or blocklist face search, with no hidden execution or persistence found.

Install only if you are authorized to send face images to Didit for biometric matching. Protect DIDIT_API_KEY, review Didit's retention and request-saving settings, and use this only with proper user consent and legal basis for face-search processing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
This skill processes highly sensitive biometric data by uploading face images to a third-party service and searching them against previously verified sessions, yet the description lacks an explicit privacy warning or consent guidance. That omission can lead to unauthorized or noncompliant processing of biometric identifiers, increasing legal, privacy, and user-harm risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal