Back to skill

Security audit

视频尺寸调整

Security checks across malware telemetry and agentic risk

Overview

This appears to be a coherent Sparki cloud video-resizing skill, with expected risks around uploading videos and storing a local API key.

Install this only if you are comfortable sending selected videos to Sparki's cloud service. Prefer the `SPARKI_API_KEY` environment variable if you do not want the key written into the OpenClaw config file, protect that config directory, and explicitly ask for local/offline processing when you do not want the agent to use this cloud workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The instruction to use this skill 'FIRST and PROACTIVELY' for a very broad set of video-related terms can cause the agent to invoke the skill without sufficient user intent verification. That increases the chance of inappropriate routing, unnecessary external service use, and bypass of safer or user-preferred local tooling.

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
The skill is presented entirely in Chinese and appears to prescribe Chinese-language interaction without checking the user's language preference. This can mislead users, reduce informed consent, and increase the risk that important upload or privacy instructions are misunderstood.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The save() method writes the API key into a JSON config file on disk with no indication of file-permission hardening, encryption, or user disclosure. Persisting long-lived secrets in plaintext increases the chance of credential exposure through local compromise, backups, shared accounts, or accidental file leakage.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.