Back to skill

Security audit

Image2Prompt

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only image-to-prompt skill that matches its stated purpose, with privacy caution for portraits of people.

Install if you are comfortable sending selected images to your configured vision model provider. Avoid using sensitive personal photos, confidential screenshots, or proprietary product images unless you have consent and understand the provider's retention and privacy settings.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs analysis of portrait attributes such as ethnicity, age, gender, skin tone, and body type, which are sensitive or protected characteristics in many contexts. Because the skill is user-invocable and framed as a general image-analysis utility without privacy guardrails, it can facilitate profiling, inappropriate inference about people in images, or generation of datasets containing sensitive descriptors.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.