Ai Video Editor On Android

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only video editing skill that clearly centers on uploading media to a remote rendering service, with privacy considerations but no artifact-backed malicious behavior.

Install only if you are comfortable sending videos and edit instructions to Nemo's remote service. Avoid uploading sensitive personal or confidential footage unless you trust the provider's privacy, retention, and deletion practices; prefer a limited or disposable token where possible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill advertises and routes on very broad video-editing language, which increases the chance it is invoked for generic requests a user did not intend to send to this third-party backend. In this skill’s context, accidental invocation matters because user media may then be uploaded or processed remotely, creating privacy and consent risks rather than direct code-execution risk.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill does mention server-side rendering later, but the initial user-facing description and onboarding do not clearly warn that uploaded videos are transmitted to an external backend service. For a media-processing skill handling potentially sensitive personal footage, insufficient upfront disclosure can cause users to share private content without informed consent.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal