Back to skill

Security audit

Vision Understanding

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent media-to-text helper, but users should know it can send images, documents, audio, or video to external model providers.

Install this if you want an agent to use external multimodal models for OCR, captions, transcription, video summaries, and similar tasks. Avoid submitting confidential screenshots, receipts, documents, audio, or video unless you are comfortable with that media being uploaded to the named providers, and redact sensitive details first when possible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
81% confidence
Finding
The skill is described as a broad 'media in, text out' handler with catch-all phrases like 'what's in this image' and 'Any media in, text out' that can overlap with many unrelated image, document, audio, or video tasks. This can cause over-invocation of the skill, potentially routing sensitive user content to external multimodal providers when a narrower or local path would have been more appropriate.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to provide media as URL or base64 and routes it to external providers such as Google, Runware, and Memories, but it does not warn that uploaded media may leave the local trust boundary. Because this skill targets high-risk content types like screenshots, receipts, documents, audio, and video, users may unknowingly transmit sensitive personal, financial, or confidential data to third parties.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.