Back to skill

Security audit

dezgo-img-gen

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple image-generation usage guide for a local freegen container, with no executable code or hidden behavior found.

Install only if you trust the local freegen container and are comfortable sending prompts, source images, and masks to it. Avoid using sensitive personal or proprietary images unless you understand that container's logging, retention, and access controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs users to send prompts and base64-encoded images to a local HTTP service at `http://freegen:3000`, but it does not warn that user-supplied content will be transmitted to another service for processing. This can mislead users and operators about data flow, creating privacy and trust risks, especially because prompts and images may contain sensitive personal or proprietary information.

VirusTotal

38/38 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.