Back to skill

Security audit

Character Consistency

Security checks across malware telemetry and agentic risk

Overview

This skill gives coherent guidance for using user-provided reference images to keep generated characters or products consistent, with a privacy note users should consider.

Before using this skill, treat reference images as data sent to the image-generation provider. Avoid using private faces, confidential product images, or copyrighted material unless you have permission and are comfortable with the provider's handling of those inputs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The examples instruct users to provide external reference image URLs and discuss accepted image sources, but they do not warn that these images will be transmitted to a third-party image-generation service and may contain personal, sensitive, or proprietary content. In a character-consistency skill, reference images are central to the workflow, so users are especially likely to upload identifiable faces or branded assets, increasing privacy and confidentiality risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.