Ai Video Maker Sora

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only skill for sending user-provided prompts and files to a NEMO Video cloud API to generate and export videos.

Install only if you are comfortable sending prompts, uploaded documents/media, generated content, and session state to the NEMO Video API. Avoid sensitive uploads unless you trust that third-party service’s privacy and retention practices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The routing table sends all unmatched prompts to the SSE generation/editing workflow, which effectively turns ambiguous or unexpected user input into backend actions. In a skill that can create sessions, upload content, and issue edit/render requests, this increases the chance of unintended API calls, prompt-triggered state changes, and unsafe handling of malformed or adversarial input.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal