Back to skill

Security audit

Ai Image Prompt Tool Free

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be an image-prompt helper, but it asks for command execution and has broad trigger wording that does not match that limited purpose.

Install only if you are comfortable with a prompt-writing skill that declares command execution despite not needing it. Prefer a version with exec removed and use it only for image prompt drafting or optimization; review any English-converted prompts before using them in an image model.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill claims it is a pure Markdown skill that does not require exec capability, yet it declares `allowed-tools: read exec` and includes command-line execution examples elsewhere. This inconsistency can mislead users and reviewers about the actual execution surface, increasing the chance that the agent is granted unnecessary command execution privileges.

Intent-Code Divergence

Low
Confidence
82% confidence
Finding
The trigger conditions say the skill should be used for marketing copy, writing, title optimization, and content creation, which do not match the stated purpose of image-prompt generation. This mismatch can cause the agent to invoke the skill in unrelated contexts, leading to inappropriate handling of user requests and expansion of the skill's operational scope beyond what users expect.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger condition is overly broad and mismatched to the skill's stated purpose, allowing activation for generic content-generation tasks. Overbroad routing logic is dangerous because it can cause this skill to intercept unrelated prompts, override better-suited tools, and potentially expose users to unnecessary tool access or unintended transformations.

Natural-Language Policy Violations

Medium
Confidence
78% confidence
Finding
The skill recommends converting prompts into English because image models may perform better, but it does so as default guidance without clear user consent. In practice, this can override user language preferences, alter meaning, or unexpectedly transmit sensitive content into another language representation, which is especially problematic when precise wording matters.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.