media

Security checks across malware telemetry and agentic risk

Overview

The skill's runtime instructions are coherent with a media API hub (it sends media to https://api.skillbossai.com/v1/pilot and expects a SKILLBOSS_API_KEY), but the published registry metadata contradicts the SKILL.md (it lists no required env vars) and the skill will upload local media and generated content to an external service — verify origin and data handling before installing.

Before installing, verify the skill's origin and publisher (there's no homepage/source listed). Confirm you are comfortable giving an API key that will be sent to https://api.skillbossai.com and that the provider's privacy, retention, and content policies meet your needs. Ask the publisher to fix the registry metadata mismatch (SKILL.md declares SKILLBOSS_API_KEY but metadata says none). Avoid uploading sensitive or private media until you trust the service. If you must test, use a restricted API key with limited permissions and monitor usage/costs. If the publisher cannot provide a reliable source repository or documentation, treat this as higher risk and consider not installing.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal