Podcast Clipper ( Subscut )

Security checks across malware telemetry and agentic risk

Overview

This skill is a narrow wrapper that sends a user-provided video URL to Subscut to generate short clips, with no hidden install behavior or unrelated capabilities found.

Install this only if you intend to use Subscut for clipping. Use public or authorized video URLs, avoid submitting confidential media unless you accept Subscut's handling of it, and keep the API key in environment configuration rather than hard-coding it in shared files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The example invokes a remote clipping API using a user-supplied video URL, but the script provides no disclosure that media URLs and associated content metadata will be transmitted to an external service. In a skill specifically designed to process podcasts and videos through Subscut, this omission can mislead users about data flow and create privacy, confidentiality, or compliance issues when the source media is non-public or sensitive.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal