Back to skill

Security audit

Logo Design Tool Free

Security checks across malware telemetry and agentic risk

Overview

This is a logo-design guidance skill with some broad but disclosed tool and external-service use, and no evidence of hidden, destructive, or deceptive behavior.

Before installing, treat this as a practical logo-prompting guide that may use third-party AI image tools. Avoid submitting confidential brand plans, unreleased names, customer data, or proprietary assets unless you are comfortable with the chosen image provider's terms. The ping/network troubleshooting note is not central to the skill and should only be used when you intentionally want basic connectivity diagnostics.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill is a logo-design guidance skill, but its error handling instructs users to run network diagnostic shell commands like `ping`, which is outside the declared functional scope. This expands the agent's operational behavior into system/network interaction and can normalize executing shell commands in response to unrelated failures, increasing the chance of misuse or unsafe command extension in tool-enabled environments.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill declares very broad activation and coverage keywords that overlap with generic creative and workflow requests, which can cause the agent to invoke this skill in contexts far beyond simple logo design. In a tool-enabled environment, overbroad routing increases the chance that unrelated user requests are funneled into a skill that encourages external service use and some execution-capable behavior.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill repeatedly directs use of external AI image generation services but does not warn that prompts, brand concepts, and possibly uploaded assets may be transmitted to third-party platforms. This omission can lead users to disclose sensitive business or personal information without informed consent, especially during branding work that may involve unreleased product names or proprietary concepts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.