Back to skill

Security audit

video

Security checks across malware telemetry and agentic risk

Overview

This video-production skill is coherent and mostly advisory, with a limited note that it may read named product-marketing context files if present.

Before installing, be aware that if you keep sensitive strategy or customer details in the named product-marketing context files, the agent may use that information when planning videos. Review those files and avoid putting secrets or unrelated confidential data there.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to read local project files for product-marketing context before asking the user, without requiring user awareness or consent at runtime. This creates a data exposure risk because local files may contain sensitive business plans, internal messaging, customer details, or secrets unrelated to the immediate task, and the accessed content could then influence outputs or be disclosed downstream.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.