短视频创作全能工具

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed short-video, script, lyric, and style-consistency guide with no hidden code or privileged behavior found.

Install this if you want a broad creative assistant for short-video planning, lyrics, prompts, and style-consistent follow-up videos. Avoid uploading private, sensitive, copyrighted, or third-party reference videos unless you have permission, and only run the FFmpeg examples on media files you intend to process.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases include very broad, common creative requests such as writing scripts, lyrics, songs, and making videos, which can cause the skill to activate in many unrelated contexts. Overbroad activation increases the chance of unintended invocation, prompt hijacking of normal user workflows, and accidental exposure of the model to skill-specific instructions when the user did not request this tool.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger words include very generic creative phrases such as '写剧本', '写歌词', '创作视频', and '写歌', which are likely to appear in many ordinary user requests. This increases the chance the skill activates when the user did not intend to invoke it, causing inappropriate routing, unexpected behavior, or disclosure of the skill's capabilities in unrelated contexts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal