Free Avatar Video

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed cloud avatar-video skill with privacy considerations, but no hidden code, destructive behavior, or purpose-mismatched access was found.

Install only if you are comfortable sending scripts, prompts, and uploaded media to NemoVideo for cloud processing. Avoid confidential files, use a dedicated or anonymous token when possible, and remember that remote sessions, credits, and retention are governed by the external service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The routing table sends virtually all unmatched user input to the SSE generation workflow, which can cause the skill to forward unintended or ambiguous prompts to the remote backend. In a cloud-connected skill that can upload, edit, and render content, this increases the chance of accidental data disclosure or unintended billable/actions on behalf of the user.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The user-facing description emphasizes functionality but does not clearly disclose that prompts, scripts, and uploaded files are transmitted to third-party cloud endpoints for processing. This is a privacy and consent issue, especially because the skill accepts documents and media files up to 200MB and automatically connects to external services on first use.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal