Back to skill

Security audit

Image2 广告图片|可归因测图单元

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent ad-image generation helper that uploads only user-specified product images to AI Hive and does not show hidden posting, account access, or unrelated data collection.

Before installing, be aware that product images you pass with --product-source are uploaded to AI Hive, and the auth command stores your AI Hive API key locally. Use brief mode to preview prompts without upload, and only provide images and claims you are authorized to send to that service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill instructs users to run local Python commands that read files, write state, access environment variables, invoke shell commands, and make outbound network requests to an external API, yet the skill declares no permissions. This creates a transparency and policy gap: users or hosting systems may treat the skill as documentation-only while it actually has operational code capabilities, increasing the risk of unintended data exposure or unreviewed execution.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.