Back to skill

Security audit

Jimeng Prompter

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-writing skill with disclosed local preference memory and no evidence of malware, exfiltration, or unsafe installation behavior.

Install only if you are comfortable with a skill that may keep and reuse local visual-style preferences in references/evolution-memory.md. Use the documented skip or clear commands if you do not want memory, and invoke the skill explicitly for Jimeng prompt generation to avoid accidental activation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill claims preference-memory reads and writes are consent-gated, but the workflow explicitly instructs automatic reading of `references/evolution-memory.md` at every startup before Phase 1. That creates a privacy-consent mismatch: previously stored user preferences are accessed by default without a fresh read consent check, which can expose cross-session personal preferences unexpectedly.

Intent-Code Divergence

Low
Confidence
74% confidence
Finding
The document promises users can delete preference records at any time, but the operational instructions do not define an implemented deletion flow beyond a policy statement. This can mislead users into believing deletion is available and immediate when the skill specification does not actually ensure that behavior.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The file explicitly states that visual preferences are recorded across sessions and automatically reinjected into future prompts, and that updates are automatically appended after each session. In a skill advertised as privacy-first and consent-gated, this creates a credible privacy and transparency risk because users may be tracked or profiled across sessions without clear, per-use consent if the implementation follows this documentation.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The instruction that memory is 'automatically appended after every session' directly suggests unconditional persistence of user preference data. Even if other files claim consent gating, contradictory guidance in this file can cause an agent or maintainer to implement non-consensual data retention, undermining privacy guarantees and increasing the chance of unauthorized cross-session profiling.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The image-related trigger examples are very broad natural-language phrases that overlap heavily with ordinary user requests, making accidental invocation more likely in environments where skills are selected from conversational text. While not a direct code-execution flaw, ambiguous activation can cause the wrong skill to capture user intent, leading to misrouting, privacy surprises, or unintended prompt transformation.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The video invocation examples are similarly underspecified and do not clearly bind activation to a specific platform or prompt-engineering function. In agent ecosystems that rely on semantic matching, this increases the chance of unintended activation during ordinary creative-assistance requests, which can interfere with user expectations or route content into a more powerful skill than intended.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger conditions include broad, everyday phrases such as '生成一个' plus a description, which can cause the skill to activate in contexts the user did not intend. Unintended invocation is dangerous here because the skill may begin preference-memory handling and steer the conversation into a specialized workflow without clear user initiation.

Natural-Language Policy Violations

Medium
Confidence
77% confidence
Finding
The skill hardcodes Chinese-language interaction patterns without offering user language choice, which can reduce user comprehension of consent, privacy, and workflow prompts. In a skill that handles preference memory and consent decisions, language inflexibility increases the chance users misunderstand what is being read or stored.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.