Back to skill

Security audit

Rendshot

Security checks across malware telemetry and agentic risk

Overview

Rendshot is a coherent image rendering and screenshot helper, but users should treat it as a third-party service that may receive prompts, HTML, template data, URLs, and an API key.

Install only if you are comfortable sharing render inputs, prompts, template variables, screenshot target URLs, and a Rendshot API key with Rendshot or your configured self-hosted endpoint. Avoid sensitive HTML, secrets, authenticated pages, localhost/internal URLs, cloud metadata endpoints, and regulated data unless you have explicit authorization and controls in place.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad enough to match common requests like 'generate thumbnail' or 'screenshot this page,' which can cause the skill to activate unexpectedly. In a skill that can fetch external URLs and render arbitrary HTML, over-broad invocation increases the chance of unintended network access, privacy issues, or misuse without clear user intent.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill describes screenshot and rendering capabilities but does not warn that using them may fetch third-party URLs or process untrusted HTML/CSS. This can lead users or upstream agents to submit sensitive internal URLs, authenticated pages, or attacker-controlled content without understanding the privacy and security implications.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal