Dream Image to Video

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple image-to-video API guide whose external upload behavior fits its purpose, though users should treat uploaded images as shared with third-party services.

Install only if you are comfortable providing a DreamAPI/NewportAI API key and sending prompts, image URLs, and any uploaded local images to external services. Avoid sensitive, private, regulated, or confidential images unless you have reviewed the provider's data handling terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill documentation states that local files must be uploaded to OSS before use, but it does not clearly warn users that their local content will be transmitted to external storage/services. This is a real transparency and privacy issue because users may supply sensitive images assuming processing is local or limited to a single API endpoint.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal