Skill Bundle

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate cloud video-editing skill, but it can send media/project data to Levea and create exports after edits.

Install only if you are comfortable using Levea's cloud service with your API key and video/project data. Use requirePlanApproval for important, sensitive, or destructive edits, review outputs before publishing, and be aware that mutating edits may automatically render and create artifact URLs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill advertises itself for a very broad set of user intents, including many generic editing requests, without defining clear boundaries for when it should or should not be invoked. In an agent setting, this can cause over-triggering and unintended routing of user content to a remote video-editing service, increasing the chance of unnecessary data exposure or unintended mutations.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documentation states that mutating calls may automatically trigger export as a second run, but it does not consistently foreground that this causes additional server-side processing, artifact creation, and possible external storage/URL generation. Users or higher-level agents may believe they are only editing a scene when the system also transmits data for rendering and produces downloadable artifacts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal