Back to skill

Security audit

Restore And Upscale

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only image restoration and upscaling skill with minor routing ambiguity around video, but no hidden execution, persistence, or unrelated data access.

Before installing, be aware that this skill may guide an agent to send supplied images, and possibly videos, to external model workflows for restoration/upscaling. Clarify requests that use vague words like "enhance" if you mean editing or beautification rather than faithful cleanup, and prefer a dedicated video-upscale skill for video workflows if your environment separates image and video tools.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The examples file includes a full video-upscaling workflow even though the skill metadata explicitly scopes the skill to images and instructs users to use a separate `video-upscale` skill for video. In an agentic system, embedded examples strongly influence tool selection and behavior, so this contradiction can cause the agent to process out-of-scope video requests through the wrong skill, bypass routing, policy separation, or specialized controls attached to the intended video skill.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrase "enhance" is overly broad and can match many unrelated user requests, increasing the chance this skill is invoked when the user intended a different image operation. Misrouting is not likely to cause direct compromise, but it can lead to unintended processing, confusion, or use of a model path that alters content contrary to user intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.