Back to skill

Security audit

精准中文文字商业图片|GPT Image 2 文案合同

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI image-generation helper that uploads user-selected images to AI Hive and saves generated outputs, with no evidence of hidden or unrelated behavior.

Install only if you are comfortable providing an AI Hive API key and uploading the specific source images named in your commands. Treat generated text as a draft: manually verify prices, dates, legal text, packaging claims, QR codes, and other mandatory content before publishing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill invokes a local Python script with capabilities including environment access, file read/write, shell execution, and outbound network access, but it does not declare permissions or clearly bound those capabilities in a machine-enforceable way. Even though the documented workflow appears legitimate, an undeclared-capability skill increases the risk that users or hosts will execute it with broader access than expected, enabling unintended file access, data exfiltration, or misuse of supplied API keys.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.