Tiktok Video Editor App

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a cloud-backed content generation tool, but it will connect to NemoVideo and create an anonymous session when used.

Install only if you are comfortable with the skill contacting NemoVideo, creating an anonymous service session, and sending any prompts or files you choose to process to that cloud backend. Do not use it with confidential media or private text unless you trust the provider and understand its retention and privacy terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs the agent to automatically contact an external backend, generate a client identifier, obtain an anonymous token, and create a session on first open without a clear prior user notice or consent step. This is dangerous because it initiates network activity and account/session creation automatically, potentially transmitting metadata and preparing a remote processing context before the user has affirmatively chosen to connect or upload content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal