doubao-image

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a straightforward Doubao image generator that uses a Volcengine API key and sends prompts to the provider to create images.

Install only if you are comfortable using a Volcengine API key and sending image prompts to Volcengine for processing. Avoid putting secrets, personal data, or confidential business details in prompts, expect API quota or billing use, and check DOUBAO_IMAGE_OUTPUT_DIR if you customize where generated images are saved.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill documentation indicates use of environment variables and outbound network access, but it does not declare corresponding permissions. This creates a transparency and governance gap: users and hosting platforms may not realize the skill can read secrets and send data externally, which can lead to unintended exposure of API keys or user-provided prompts.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill sends user prompts to an external image-generation API, but the description does not clearly warn users that their input and related metadata leave the local environment. This is dangerous because prompts may contain sensitive business, personal, or confidential data that users would not have shared if the external transmission were clearly disclosed.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal