Text To Video Ai 2026

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent cloud text-to-video integration, but users should treat prompts and uploaded media as data sent to an external provider.

Install only if you are comfortable using the Nemovideo cloud backend. Avoid submitting confidential scripts, private media, proprietary plans, or sensitive files unless you trust that provider's data handling and retention practices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to automatically connect to a remote cloud backend, obtain an anonymous token, create sessions, and later upload prompts or files, but it does not require clear user consent or upfront disclosure that user content will be transmitted off-device. In a text-to-video skill, prompts may contain proprietary scripts, marketing plans, or sensitive media, so silent network actions create a meaningful privacy and data-handling risk even if the backend is legitimate.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal