Ai Video Editor In Free

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only cloud video editing skill whose network use and media uploads are aligned with its stated purpose, but users should understand that selected media is processed by NemoVideo.

Install only if you are comfortable sending selected clips, images, audio, and editing instructions to NemoVideo's cloud service. Avoid recordings that show passwords, private messages, customer data, or confidential screens, and be aware that free credits or export limits may apply.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The suggested invocation phrase "edit my raw video clips" is broad enough that ordinary user conversation could unintentionally trigger the skill. Because this skill uploads user media to a third-party cloud backend and creates remote sessions automatically, accidental activation can lead to unintended data transfer and external processing of potentially sensitive content.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill handles potentially sensitive user media but does not clearly warn upfront that files and prompts are sent to a remote cloud service for processing. In this context, that omission is security-relevant because the workflow includes automatic backend connection, anonymous token acquisition, session creation, and upload to an external API, which can expose private recordings or embedded secrets without sufficiently informed user consent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal