Video Animation

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed cloud video-animation connector, but users should know their media, prompts, token, and project state are sent to NemoVideo's remote service.

Install only if you are comfortable sending selected images, videos, audio, prompts, and project state to NemoVideo for remote processing. Treat NEMO_TOKEN as a credential, avoid confidential or regulated media unless you trust that service, and ask the agent to clarify before sending ambiguous prompts or exporting work that may consume credits.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill encourages users to upload media and issue prompts, but the user-facing description does not clearly warn that both files and prompts are transmitted to a third-party remote backend for processing. This can mislead users into sharing sensitive media or text under the false impression that processing is local, creating a privacy and data-handling risk.

Session Persistence

Medium
Category
Rogue Agent
Content
version: "1.0.0"
displayName: "Video Animation — Animate Images Into Video Clips"
description: >
  Get animated video clips ready to post, without touching a single slider. Upload your images or video clips (MP4, MOV, PNG, JPG, up to 500MB), say something like "animate these images into a smooth 30-second explainer video with motion effects", and download 1080p MP4 when it's done. Built for marketers and content creators who move fast and want to create animated videos without learning complex animation software.
metadata: {"openclaw": {"emoji": "🎬", "requires": {"env": ["NEMO_TOKEN"], "configPaths": ["~/.config/nemovideo/"]}, "primaryEnv": "NEMO_TOKEN", "variant": "greeting_v2"}}
---
Confidence
81% confidence
Finding
create animated videos without learning complex animation software. metadata: {"openclaw": {"emoji": "🎬", "requires": {"env": ["NEMO_TOKEN"], "configPaths": ["~/.config

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal