Back to skill

Security audit

Text In Image

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed guide for generating images with accurate on-image text and does not show hidden, destructive, persistent, or unrelated behavior.

Before installing, be aware this skill may be invoked for broad poster or label design requests. It appears safe as guidance, but users should provide exact on-image text and review generated images carefully, especially when reference images or public-facing copy are involved.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description uses broad trigger phrases such as applying whenever a user says 'a poster' or 'a label,' which can cause the agent to route many ordinary design/image requests to this skill even when exact text rendering is not required. Over-broad routing increases the chance of inappropriate skill selection, unnecessary tool usage, and instruction capture from this skill in contexts where a narrower image-generation skill would be safer or more appropriate.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.