Tianshu Image

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a straightforward text-to-image connector for Alibaba DashScope, with expected API-key and prompt-sharing risks but no hidden or destructive behavior found.

Install only if you are comfortable sending image prompts to Alibaba Cloud DashScope and using a DashScope API key that may consume quota or incur charges. Prefer environment/config storage over passing the key on the command line, avoid including secrets or sensitive personal data in prompts, and save generated images only to intended paths.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill tells the agent to send a user-provided prompt to Alibaba Cloud DashScope but does not clearly warn that user content is transmitted to a third-party cloud service. In context, prompts may contain sensitive personal, proprietary, or regulated information, so lack of disclosure can lead to unintentional data exposure.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal