Emergence Video Producer

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed video-production helper, with ordinary caution needed around external tools, narration text, and output files.

Install only if you trust the local WebReel, FFmpeg, Edge-TTS or DashScope, and Pillow setup. Review the storyboard, generated config, target URL, narration text, and output path before production, and use a dedicated output directory to reduce accidental overwrites.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding
The skill instructs the agent to use shell-capable tools and environment-based credentials, but the metadata shown declares no permissions. That creates a transparency and policy gap: agents or users may invoke a skill believing it is documentation-only when it actually drives command execution and accesses secrets, increasing the chance of unintended command execution or credential exposure.

Tp4

High
Category
MCP Tool Poisoning
Confidence
76% confidence
Finding
The documented behavior does not align with the detected capabilities and omissions: the skill advertises a specific video pipeline, but supporting behavior is incomplete and some additional tooling is undisclosed. This mismatch is dangerous because reviewers and operators cannot accurately assess what will execute, what dependencies are needed, or what artifacts and subprocesses will be touched, which weakens trust boundaries and can hide unsafe behavior.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The script passes -y to ffmpeg, which forces overwrite of the destination file with no confirmation. In an automated pipeline, a mistaken or attacker-influenced output path could silently destroy existing files or replace artifacts, especially if the script runs with elevated privileges or in shared workspaces.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal