Back to skill

Security audit

Video Generation

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent CellCog video-generation integration, but users should treat prompts and media as data sent to an external service.

Install only if you are comfortable sending video prompts, scripts, and any source media to CellCog for processing. Avoid submitting secrets, confidential business data, regulated data, or personal media unless your organization permits it and you have reviewed CellCog's data handling terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill routes user prompts and potentially source media to an external video-generation service, but the described usage does not clearly warn users that sensitive prompts, scripts, images, or other uploaded assets may leave the local environment and be processed by a third party. This can lead to unintentional disclosure of proprietary, personal, or regulated data, especially because the skill encourages broad content creation workflows and references file handling in a separate skill rather than disclosing data handling here.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.