Ai Video Editor Api

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed cloud video-editing skill that sends selected media and edit prompts to NemoVideo for processing.

Install only if you are comfortable sending chosen videos, images, audio, prompts, and render state to NemoVideo's cloud service. Avoid sensitive, regulated, or private footage unless you have reviewed the provider's retention, deletion, privacy, and billing terms, and keep NEMO_TOKEN scoped to this service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The routing table sends 'Everything else' to the SSE editing action, which is an overly broad catch-all for a skill that can upload media, mutate editing state, and trigger cloud-side processing. This increases the chance that unrelated or ambiguous user prompts are interpreted as actionable editing commands, causing unintended remote operations, credit consumption, or processing of user media without sufficiently explicit intent.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs users to send raw video footage to a cloud backend but does not prominently warn that files and editing instructions are uploaded to and processed by a remote third-party service. Because user media may contain sensitive visual, audio, location, or personal data, the missing disclosure can lead to uninformed data exposure and privacy violations, especially in enterprise or regulated contexts.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal