Manim Animation En

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Manim video-rendering helper, with disclosed local rendering and optional Google TTS network use, but users should avoid cloud TTS for private narration text.

Install only if you are comfortable running local Python, Manim, and ffmpeg tooling. Review generated scene files before rendering, use offline pyttsx3 for confidential scripts or regulated content, and clear media/voiceover caches after sensitive projects.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The guide explicitly recommends multiple cloud TTS providers that require network access but does not warn that narration text may be sent to third-party services. In this skill context, users may provide proprietary educational content, internal scripts, or sensitive text for narration, so omission of a privacy disclosure creates a real data-exposure risk.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The example sets GTTSService as the speech backend without any indication that gTTS is an online service. In practice, this can cause users to unknowingly transmit narration text over the network to Google-backed infrastructure, which is especially risky if the generated video script contains confidential or regulated information.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal