Back to skill

Security audit

gpt-image

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent RunAPI GPT Image helper with no executable payload, but users should remember that prompts and images are sent to an external service.

Install only if you intend to use RunAPI for GPT Image. Treat prompts, uploaded images, masks, and related metadata as data sent to RunAPI and upstream providers, and avoid sending confidential or personal content unless that is acceptable for your use case.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill directs users to send prompts and image-editing inputs to RunAPI/OpenAI but does not clearly warn that those prompts, images, and possibly sensitive embedded content will leave the local environment and be processed by third-party services. In an agent setting, users may assume a local-only image operation, so the omission can cause unintended disclosure of confidential images, personal data, or proprietary material.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.