Back to skill

Security audit

Vox Director

Security checks across malware telemetry and agentic risk

Overview

This is a creative video-generation skill that openly relies on Atlas Cloud and local video tools, with no hidden installer or malicious scan evidence, but prompts and media may leave the local machine.

Install only if you are comfortable using Atlas Cloud and related model providers for the creative workflow. Avoid sensitive or proprietary topics, scripts, images, brand assets, or personal references unless you understand the provider terms and data handling. Also verify that the referenced companion scripts and reference files are actually available before expecting the automated workflow to run.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill advertises very broad trigger phrases such as 'collage video', 'motion collage', and 'turn this topic into a collage video', which can match many ordinary creative requests beyond the narrow intended workflow. In an agent environment, over-broad activation can cause the skill to intercept unrelated user tasks and route them into a cloud-backed automation pipeline unexpectedly, increasing the chance of unintended tool use, data exposure, and user surprise.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill says it runs on Atlas Cloud API and local ffmpeg, but it does not provide a clear user-facing warning that project content, prompts, scripts, and possibly brand/person references will be transmitted to external cloud services. That omission undermines informed consent and can lead users to submit sensitive or proprietary material without realizing it leaves the local environment.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.