Back to skill

Security audit

AITuber AI Video Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AITuber API helper for creating and downloading AI videos, with expected account and credit-related API use.

Install this only if you want your agent to use your AITuber account to create videos. Treat AITUBER_API_KEY as a secret, avoid sending confidential scripts or ideas unless you are comfortable sharing them with AITuber, confirm generation/export actions that may consume credits or require a paid subscription, and review the optional MCP server before enabling it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The README instructs agents and users to obtain an API key and perform credit-sensitive, account-related, export, and download operations, but it does not warn that prompts/scripts and account metadata are sent to a third-party service or that actions may consume paid credits. In an agent-skill context, this omission is more dangerous because the document is effectively operational guidance for autonomous tools, increasing the chance of silent external transmission, unexpected billing, and accidental access to subscription or download data.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.