volcengine-image-generate

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Volcengine image generator, with minor documentation gaps about remote prompt processing and local downloads.

Install only if you are comfortable sending prompts to Volcengine/Ark and using your API quota. Do not include secrets or confidential data in prompts, set only the intended API key environment variables, install the SDK from a trusted source, and run the script from a directory where saving generated PNG files is acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to provide a prompt to an image-generation script but does not warn that the prompt content is sent to an external service. Users may include sensitive, proprietary, or personal information in prompts without realizing it will leave the local environment, creating a data exposure risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal