Back to skill

Security audit

spark-media

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed media-generation skill that uses a configured API key to send prompts and optional images to a specific external service.

Before installing, confirm you trust the ai-skills.open-idea.net service with prompts and any images you choose to send, configure the API key only through the documented environment variable, and avoid uploading sensitive images unless you have consent and need them for the task.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The manifest description is written as a Chinese-only usage directive ("使用场景") and the document consistently presents the skill in Chinese without indicating that other languages are supported or that Chinese is required for a specific regional/compliance reason. Per the policy, language or locale constraints should either be optional for the user or explicitly justified.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.