Back to skill

Security audit

Pixel Asset Compiler

Security checks across malware telemetry and agentic risk

Overview

This skill coherently helps compile sprite sheets into validated game assets, with its file writes and CLI use aligned to that purpose.

Before installing, confirm you intend to use the pixel-asset-compiler CLI and are comfortable with a global npm install if the CLI is not already present. Run it only on sprite/input directories and output paths you choose, since compilation and export will create or overwrite generated asset files there.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/run-workflow.mjs:45