Back to skill

Security audit

Image Handoff

Security checks across malware telemetry and agentic risk

Overview

This skill is a small image-request handoff helper, but users should know it forwards prompts to another agent and records request details in memory.

Before installing, confirm you are comfortable with image prompts being sent to an artist agent and logged in memory. Ambiguous requests should be confirmed before handoff, and sensitive personal or confidential details should be avoided unless the surrounding system provides retention and deletion controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The auto-detection patterns are broad enough to match ordinary conversation and lack exclusion rules, which can cause unintended routing of user requests to another agent. In a multi-agent system, that can leak user content to an unnecessary downstream component and produce actions the user did not clearly authorize.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs persistent logging of prompts, model details, results, and user feedback without any notice, minimization, or consent mechanism. Image prompts can contain sensitive personal, medical, financial, or confidential information, so silent retention increases privacy and data-governance risk.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.