Back to skill

Security audit

Ai Image Gen Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a text-to-image helper that uses a user-configured external image API, with some scope and privacy cautions but no hidden or destructive behavior found.

Install only if you are comfortable configuring a third-party image API key and sending your image prompts to that provider. Avoid including secrets, personal data, confidential business details, or regulated information in prompts, and treat the referenced missing script as something you would need to supply or verify separately.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger condition is overly broad ('use when AI model calling, intelligent dialogue, agent orchestration, LLM applications are needed'), which can cause this skill to activate in many unrelated conversations. Because the skill has exec permission and routes user input toward external image-generation workflows, accidental invocation can lead to unintended command execution paths, user confusion, or unnecessary data transmission to external services.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs users to configure an external API endpoint and send prompts to a third-party image API, but it does not clearly disclose that user prompts may contain sensitive or personal data that will be transmitted off-platform. In an agent setting, users may unknowingly submit confidential text, leading to privacy leakage or compliance issues, especially because prompts can include detailed personal, business, or copyrighted content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.