Back to skill

Security audit

Ai Artist Workstation

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly coherent for AI image-order fulfillment, but it asks agents to handle customer face photos, cloud delivery, ecommerce messaging, refunds, and shell troubleshooting without enough user-control or data-handling boundaries.

Review this skill carefully before installing. Use it only with customer consent for sending prompts and face/reference images to third-party AI services and cloud storage. Confirm which ecommerce or cloud accounts it can use, require approval before refunds or customer messages, and avoid enabling unrestricted command execution unless your agent environment already contains suitable controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill describes sending prompts and reference photos to external AI services, downloading results locally, and sharing outputs through cloud links, but it does not provide a clear user-facing consent and data-handling warning. This is dangerous because users may unknowingly expose sensitive personal images, biometric-like face data, prompts, or customer assets to third parties and local storage outside their expectations.

Missing User Warnings

Low
Confidence
92% confidence
Finding
The skill instructs the agent to automatically execute troubleshooting commands such as ping during timeout or delivery failures without a clear warning or approval gate. This is dangerous because command execution expands the attack surface, may leak network metadata, and normalizes running shell commands based on operational states rather than explicit user intent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.