Back to skill

Security audit

口播视频剪辑

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Sparki cloud video-editing skill, but users should know it uploads selected videos to Sparki and can save a Sparki API key locally.

Install this if you want Sparki cloud-based video editing. Do not use it for sensitive videos that must stay local, prefer SPARKI_API_KEY from the environment if you do not want the key saved to disk, and avoid custom API base URLs unless you fully trust them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The instruction to use the skill 'FIRST and PROACTIVELY' for a very broad set of video-related terms can cause the agent to invoke this skill even when a simpler, safer, or more appropriate workflow would suffice. That increases the chance of unnecessary file access, external API usage, and user steering into a third-party service without clear need or consent.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The save() method persists the API key into a JSON file under the user's home directory without any explicit warning, consent flow, or permission hardening. Storing long-lived secrets on disk increases exposure to local compromise, accidental backup/sync leakage, and unintended disclosure to other processes or users on the system.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.