Free Generator Text

Security checks across malware telemetry and agentic risk

Overview

The skill appears aimed at remote generation/editing, but it may connect to a backend and route ambiguous requests into authenticated edit actions too automatically.

Review this before installing. Use it only if you are comfortable with a remote service receiving generation/edit requests and uploaded content. Look for a clear consent step before backend connection, token/session creation, and any edit request; avoid sending private files until that behavior is explicit and scoped.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The routing table sends essentially all unmatched prompts to the SSE generation/edit path, which can cause unintended network actions and backend-side edits from ambiguous or incidental user input. In a skill that uploads content and issues authenticated API calls, such a broad fallback increases the chance of overbroad action execution without explicit user confirmation.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs automatic connection to a remote backend on first open, including token acquisition and session creation, without clear opt-in or a meaningful warning that network requests, token handling, and persistent session state will occur. This creates a privacy and consent problem because the user may trigger external authentication and session establishment merely by opening the skill.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal