Back to skill

Security audit

Avatar Generator

Security checks across malware telemetry and agentic risk

Overview

This is a local avatar-generation skill with only minor setup and over-triggering caveats.

Before installing, confirm you are comfortable using Python packages from your normal package source. Expect local PNG files to be created in the chosen output folder, and use explicit prompts when you want only one platform or style.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes generic phrases like "Generate avatar" and "Make social media avatar," which are common user requests and can cause this skill to activate outside a narrowly scoped invocation. Overly broad activation can route unrelated requests into this skill unexpectedly, causing incorrect tool use, unintended file generation, or interference with safer/more appropriate skills.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The usage example "Create social media avatars" is broad and teaches the agent that a generic request should invoke this skill for all platforms. That increases the chance of over-triggering and excessive actions, especially when a user may only want advice, a single image, or a different media-related task.

VirusTotal

50/50 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.