Back to skill

Security audit

Sv Storyboard Planner

Security checks across malware telemetry and agentic risk

Overview

This appears to be a normal storyboard-planning skill with only a minor risk of activating in broader creative conversations.

Install is reasonable if you want help planning short-form video storyboards. Be aware it may be invoked for generic storyboard or shot-list requests, so confirm the agent is applying this skill only when that is the workflow you intended.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The README lists very broad trigger terms such as 'storyboard', 'shot list', and 'visual plan' without constraints that tie invocation to this specific skill or workflow. This can cause unintended activation in unrelated conversations, leading the agent to surface or apply the skill when the user did not intend it, which is a genuine security and reliability issue even though the content itself is non-sensitive.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list contains very broad phrases such as 'storyboard' and 'shot list' that are common across many creative, filmmaking, and editing contexts. This can cause the skill to be invoked when the user did not intend to use it, increasing the chance of prompt-routing errors, irrelevant actions, or accidental exposure of user context to the wrong skill.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.