Video Understanding

Security checks across malware telemetry and agentic risk

Overview

This is a small, disclosed video-analysis skill that may fetch video metadata or use video tools, but I found no hidden execution, persistence, or destructive behavior.

Install only if you want your agent to analyze video links or metadata. Use trusted video URLs, avoid private videos unless you intend to share them with platform/API tools, and prefer safe argument-based command execution if adapting the yt-dlp examples.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation scenarios are vague enough that normal conversation about videos could trigger the skill unintentionally. In an agent system, overbroad routing can cause the model to fetch external links or use APIs when the user did not clearly request that behavior, increasing the chance of privacy issues, unnecessary external requests, or unsafe tool use.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal