Back to skill

Security audit

Banner Gen Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward image-generation guide that uses an external API and local output files, with some overbroad boilerplate and privacy-notice gaps but no evidence of hidden or malicious behavior.

Install only if you are comfortable using a third-party image-generation API. Avoid submitting confidential prompts or sensitive images, keep the API key in an environment variable when possible, and review any actual script or command target before running because this package only documents placeholder uv commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
The skill includes broad, generic operation language such as create/query/modify/delete, import/reset/export, and runtime configuration that exceeds the stated image-generation scope. In an agent setting with read/write/exec permissions, this kind of overbroad instruction can encourage unsafe tool use or parameter confusion, increasing the chance of unintended file operations or execution beyond user intent.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs users to supply an API key and use a networked image-generation service without clearly warning that prompts, input images, and related metadata may be sent to an external provider. In this context, users may unknowingly transmit sensitive content or credentials-related data, creating privacy and data-handling risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.