Back to skill

Security audit

photo-captions-free

Security checks across malware telemetry and agentic risk

Overview

This caption-writing skill is not clearly malicious, but it asks for broad file and command access that does not fit its stated photo-caption purpose.

Install only if you are comfortable granting this skill broad local file and command capabilities. For ordinary photo caption writing, a safer version should remove read/write/exec tools and narrow the description to caption generation only.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as a narrowly scoped photo-caption generator, but later sections expand it into generic file handling, API integration, and command execution. This scope drift can cause an agent to grant or invoke capabilities far beyond what users expect, increasing the chance of unsafe file access, network use, or shell execution under a benign-looking skill name.

Context-Inappropriate Capability

High
Confidence
89% confidence
Finding
Generic read/write capability is unnecessary for generating social-media captions from conversational photo context and expands the attack surface to local file disclosure or unintended file modification. A misleadingly simple creative-writing skill should not be able to touch arbitrary files, especially in shared or developer environments where sensitive data may be accessible.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
Generic read/write capability is unnecessary for generating social-media captions from conversational photo context and expands the attack surface to local file disclosure or unintended file modification. A misleadingly simple creative-writing skill should not be able to touch arbitrary files, especially in shared or developer environments where sensitive data may be accessible.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The document contradicts its own stated boundary by marketing the skill as a general automation component with API, file, and command features. These contradictions make the skill more dangerous because agents or users may trust the harmless captioning description while the embedded instructions normalize broader privileged actions.

Vague Triggers

High
Confidence
84% confidence
Finding
The invocation text says the skill should be used for code generation, programming assistance, debugging, testing, and deployment, which is unrelated to photo captions. Overbroad trigger language can cause an agent to select this skill in inappropriate high-privilege contexts, where its declared exec/read/write tools become much more dangerous than the benign title suggests.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.