Back to skill

Security audit

freegen-image-generation

Security checks across malware telemetry and agentic risk

Overview

This is an image-generation helper, but it explicitly promotes an unfiltered model path as a workaround for restricted prompts.

Review this skill before installing. Its image API documentation is otherwise straightforward, but it encourages using an unfiltered route for prompts that other tools restrict. Use only if your workspace accepts that content-safety posture and the privacy/cost implications of sending prompts and images through the freegen/Dezgo service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Ssd 4

Medium
Confidence
98% confidence
Finding
The documentation explicitly gives a workaround for provider content restrictions by directing users to an 'uncensored' path when other tools block prompts. That materially lowers the barrier to generating prohibited or abusive content and amounts to bypass guidance for upstream safety controls.

Ssd 2

Medium
Confidence
96% confidence
Finding
Labeling Flux as 'uncensored' and 'kein Filter' promotes the no-filter path as a feature and implicitly encourages safety-filter evasion. Even without explicit exploit code, this frames the service as suitable for generating content that other models or tools would block.

Ssd 2

Medium
Confidence
97% confidence
Finding
The policy table advertises that one API path allows all prompts while others are filtered, effectively mapping users to a bypass route. In the context of an image-generation skill, this increases abuse risk because it operationalizes circumvention of safety restrictions for disallowed content.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.