Back to skill

Security audit

Logo Design Guide Tool Free

Security checks across malware telemetry and agentic risk

Overview

This is a logo-design guidance skill with some broad and execution-like wording, but no artifact-backed hidden, destructive, or data-exfiltrating behavior.

Install this as a logo-design reference skill, not as an autonomous generator. Be aware that it declares read/exec and mentions external AI image tools, so keep tool use user-directed and configure any third-party image-generation API keys only through the provider you intend to use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
86% confidence
Finding
The skill is presented as an educational design guide, but this section claims execution-oriented behavior such as create/query/export operations and structured result handling. That mismatch can cause an agent or orchestrator to treat passive guidance as an active tool workflow, increasing the chance of unintended execution paths or over-privileged invocation.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The scope statement claims broad support for design creation, image generation, and common creative tasks beyond the manifest's stated role as a learning/practice guide. Overbroad capability claims can trigger the skill in unrelated contexts and may cause an agent to route user requests to a skill that is not appropriately constrained.

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
This section states that the skill can achieve visual output through AI image generation tools, implying operational generation capability rather than advisory content. In an agent ecosystem, such wording can misrepresent trust boundaries and lead to unexpected tool use, especially since the manifest does not clearly declare a dedicated image-generation integration.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The keyword coverage includes very broad, common creative phrases, making unintended invocation more likely. An over-triggering skill can hijack unrelated requests, produce irrelevant or lower-trust outputs, and expand the effective attack surface of the agent routing layer.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.