Back to skill

Security audit

LinkedIn Image Generator

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only LinkedIn image-generation helper with no hidden install code or unsafe behavior found.

Safe to install for LinkedIn visual generation. Avoid putting sensitive unreleased business data, private photos, confidential logos, or regulated customer information into image prompts or saved templates unless you understand the configured provider's retention and privacy behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill description includes broad activation phrases such as 'professional post' and 'wants to create visual content for LinkedIn,' which can cause the skill to trigger on loosely related requests. Over-broad routing can lead to unintended tool use, wrong-task execution, or unnecessary exposure of internal references and generation capabilities in contexts the user did not explicitly request.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.