Ai Intelligent Image Generation

Security checks across malware telemetry and agentic risk

Overview

This appears to be a normal image-generation skill that sends user prompts and optional reference images to an external image API, with no evidence of hidden or destructive behavior.

Install only if you are comfortable sending image prompts and any reference images to the configured image-generation provider. Avoid using confidential, personal, regulated, or proprietary images unless you have reviewed the provider’s privacy and retention terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill advertises text-to-image and image-to-image generation using external services such as DALL-E API, but it does not warn users that prompts and uploaded images may be transmitted to third-party providers. This creates a real privacy and data-handling risk because users may submit sensitive images, personal data, or confidential business content without informed consent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal