Camera

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: it helps an agent take local webcam photos, but users should understand it writes captured media to /tmp.

Install only if you want an agent to activate your Mac cameras when you ask for photos. Review or delete /tmp/brio.jpg, /tmp/facetime.jpg, and the warmup mp4 files after use if you do not want captured media retained locally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs capturing images and temporary warmup videos from webcams and storing them in /tmp without any explicit privacy warning, consent check, retention guidance, or cleanup step. Because webcam output is highly sensitive and /tmp is a shared temporary storage location with uncertain retention, this can expose private visual data beyond the immediate user intent and increase the risk of unintended access or later disclosure.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal