WaveSpeedAI Watermark Remover

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only WaveSpeed skill, but it directly enables watermark, logo, caption, and overlay removal without meaningful authorization or rights-use limits.

Review carefully before installing. Use only for media you own or are clearly authorized to edit, and do not use it to remove attribution, copyright notices, platform marks, subtitles, disclaimers, or provenance indicators from third-party content. Also consider that media may be uploaded to WaveSpeed and API usage may cost money.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill is explicitly designed to remove watermarks, logos, captions, and text overlays, but it provides no warning about copyright, ownership, authenticity, or platform-policy risks. That omission makes misuse more likely by normalizing rights-management evasion and deceptive media manipulation as routine behavior.

Ssd 2

Medium
Confidence
98% confidence
Finding
The top-level description promotes watermark and logo removal as a core supported capability, which directly enables tampering with provenance, attribution, and rights indicators. In this context, the skill is not merely dual-use documentation; it operationalizes a content-manipulation workflow that can be readily used for infringement or deception.

Ssd 2

Medium
Confidence
97% confidence
Finding
The heading and introduction reinforce watermark and logo removal as normal, approved usage and provide no balancing constraints beyond generic API-security notes. Because the skill context is a turnkey media-editing integration, this framing lowers friction for abusive use and makes the capability more dangerous than a neutral technical reference would be.

Ssd 2

Medium
Confidence
96% confidence
Finding
The API documentation gives actionable instructions for removing watermarks and logos from images, which meaningfully assists misuse by showing exactly which model to call and how to invoke it. This concrete guidance increases exploitability because it turns questionable intent into a straightforward implementation path.

Ssd 2

Medium
Confidence
96% confidence
Finding
Extending the feature to video captions and overlays broadens the tampering surface from static branding to dynamic authenticity and contextual text, including subtitles, disclaimers, or source identifiers. In a video-processing workflow, this can facilitate deceptive redistribution at scale and increase downstream harm.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal