Back to skill

Security audit

AI Image Check

Security checks across malware telemetry and agentic risk

Overview

This appears to be a coherent Scam.ai image-analysis skill, but users should understand that it stores an API key locally and sends chosen images to a third-party service.

Install only if you are comfortable using Scam.ai as the processor for the images you submit. Use a dedicated, revocable API key, treat the local key file as a secret, and do not upload sensitive, private, or regulated images unless third-party processing is acceptable.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs the user to paste an API key and then save it locally in a plaintext file under the home directory. Although file mode 600 reduces exposure, the skill does not explicitly warn that the credential will persist on disk and may be accessible to local processes, backups, shell history mishandling, or other users on a compromised system.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill uploads the user's image to a third-party API for analysis but does not clearly warn the user that the file will leave the local environment. Images can contain sensitive visual content or metadata, so transmitting them externally without explicit consent creates a privacy and data-handling risk.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.