Gigma Design Canvas

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed cloud design-canvas skill with meaningful account-token and project-editing risks, but its behavior matches its stated purpose.

Install only if you are comfortable giving Gigma's hosted MCP service access to your Gigma projects. Treat the MCP link like a password, regenerate it if exposed, and avoid confidential images or designs unless Gigma's cloud processing and 7-day signed export URLs fit your needs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description includes broad natural-language trigger phrases such as 'design an image', 'create a poster', and 'make a thumbnail', which can cause the skill to be invoked in situations where the user did not explicitly intend to use this third-party cloud service. Because the skill has write/delete/export capabilities and uses a bearer-style embedded MCP token, unintended invocation could lead to unnecessary data exposure to the external service or accidental modification/export of projects.

VirusTotal

54/54 vendors flagged this skill as clean.

View on VirusTotal