Ai Video Generation

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward AI video-generation helper, with normal caution needed around installing its CLI and handling the API key.

Install only if you trust the ai-media-generator package and the ricebowl.ai account workflow. Use a dedicated API key, avoid pasting it into shared terminals, screenshots, chat logs, or shell history, and confirm model, duration, prompt, and credit cost before generating videos.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The skill instructs users to set an API key directly in the CLI without any warning about secret handling, shell history exposure, or avoiding key disclosure in shared terminals and logs. In a credential-bearing workflow, omission of basic secret-safety guidance can lead to accidental leakage of a live API key and downstream account abuse.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal