Social Video Downloader

Security checks across malware telemetry and agentic risk

Overview

This skill does what it claims: downloads clearly requested public social-media videos using yt-dlp with local temporary storage.

Install only if you are comfortable adding yt-dlp and ffmpeg locally. Use it for public videos you clearly intend to download and have rights to save or share, and prefer a trusted package manager or isolated Python environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill description and workflow do not clearly disclose important side effects: user-supplied URLs are sent to third-party platforms, media is downloaded from external services, temporary files are created locally, and those files are deleted after delivery. This lack of transparency can mislead users and operators about privacy, retention, and data-handling behavior, which is especially relevant for a downloader skill interacting with external services.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal