Back to skill

Security audit

cogvideox 生成视频

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward CogVideoX video-generation skill that uses a disclosed ZhipuAI API key and sends prompts to ZhipuAI as expected.

Install only if you are comfortable using your own ZhipuAI API key and sending video prompts to ZhipuAI. Avoid sensitive personal or business information in prompts, consider a dedicated API key with quota controls, and stop the run manually if a generation task appears stuck.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The example utterance is a common everyday request and is broad enough that a general assistant could plausibly route many ordinary user messages into this skill unintentionally. In this case the impact is limited because the skill appears to perform a single-purpose external API call for video generation, but overbroad triggering can still cause unintended invocation, unnecessary API usage, and misuse of the provided API key.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.