Back to skill

Security audit

Card Image Builder Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a local card-image rendering guide with some sloppy network-related troubleshooting text, but no evidence of hidden data access, persistence, exfiltration, or destructive behavior.

Install only if you want a local exec-capable helper for generating PNG card images. Keep its use limited to explicit rendering tasks, review output paths before running commands, and do not run network diagnostics from this skill unless you separately intend to troubleshoot your environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill markets itself as a local-only PNG rendering tool, yet its error-handling guidance introduces unrelated network diagnostics and implies network-dependent behavior. This inconsistency can mislead an agent into performing unnecessary external connectivity checks, expanding behavior beyond the declared trust boundary and increasing the chance of unintended data exposure or unsafe command execution.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The documentation explicitly claims the skill does not involve network requests, then later instructs handling network errors and testing connectivity. Contradictory operational claims are dangerous in agentic contexts because they defeat security assumptions, may bypass policy controls for local-only tools, and can cause an agent to perform undeclared network actions under false pretenses.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger conditions are overly broad, covering generic design and visual tasks that may overlap with ordinary conversation. In an agent environment, this raises the risk of accidental invocation of exec-capable behavior in contexts where the user did not intend to run local rendering commands or write files.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.