Free Maker Text

Security checks across malware telemetry and agentic risk

Overview

This skill coherently connects to NemoVideo to turn user-provided text or files into videos, but users should expect their prompts and selected uploads to be processed by a remote service.

Use this only for files and prompts you are comfortable sending to NemoVideo for cloud processing. Prefer a dedicated NEMO_TOKEN, avoid confidential or regulated material unless you trust the provider’s terms, and invoke the skill only when you intentionally want video generation or export.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The routing table sends essentially all non-matching prompts to the SSE generation/edit path, which can cause user input that was not clearly intended as a remote editing request to be forwarded to the third-party backend. In a skill that automatically connects and uploads/processes content remotely, this broad fallback increases the chance of unintended data disclosure or unintended API-side actions.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill encourages users to upload prompts and files for processing but does not clearly warn up front that those materials are sent to a remote third-party API. This creates a privacy and data-handling risk because users may share sensitive scripts, documents, or media without informed consent about external transmission and retention.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal