Back to skill

Security audit

图像

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed image-processing skill document with broad but purpose-related file, API, and command capabilities, and no hidden payload or destructive behavior was found.

Install only if you are comfortable letting the agent read and write image assets and run image-related commands. Keep API keys in environment variables, avoid giving it sensitive images unless necessary, and require user confirmation for any shell command outside a clear image-processing workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill is presented as an image-processing capability, but the documented feature set expands into generic external API access and system command execution. This broadens the operational scope far beyond the stated purpose, increasing the risk that a caller or downstream agent could use the skill as a general execution primitive rather than a constrained image tool.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Declaring generic system command execution for an image skill creates an unnecessary high-risk capability mismatch. Even without explicit exploit code in the document, exposing exec in a loosely scoped skill can enable command injection, arbitrary file access, or misuse by agents that trust the skill description.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.