China Id Photo

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a local ID-photo generator with a setup-time network/dependency caveat, not hidden or harmful behavior.

Install it in a virtual environment if possible, review the pip install command before use, and only provide photos you intend to process. Expect dependency installation and first-run model setup to contact external package/model sources, while the actual photo transformation is described as local.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill claims processing is 'completely local' and 'does not upload any data,' but it also instructs users to install packages via pip and notes that rembg may download a model on first run. This is a real integrity/transparency issue because it can mislead users about network use and trust boundaries, especially when handling sensitive personal photos.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal