Back to skill

Security audit

Real Estate Aerial Video Generator

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward AgentPMT skill for creating or fetching aerial real-estate videos, with the main caution that property addresses are sent to AgentPMT and new videos cost credits.

Install only if you are comfortable sending property addresses to AgentPMT. Use it for addresses you are authorized to submit, especially for private homes, and confirm before requesting a new video because generation is documented as a 25-credit action while fetching existing videos is free.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The schema documents actions that send a precise street address to an external service and can trigger a paid operation, but it does not warn users or calling agents about the privacy and billing consequences. This can lead to unintended disclosure of sensitive location data and unauthorized credit consumption, especially when an agent invokes the tool automatically on behalf of a user.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal