Video Editor Hiring

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed cloud video-editing connector that uploads media to NemoVideo and uses a service token, with no install-time code or hidden local execution.

Install only if you are comfortable sending your videos, edit prompts, render outputs, and NEMO_TOKEN or anonymous trial token to NemoVideo's cloud service. Avoid highly sensitive or regulated footage unless you have reviewed the provider's account, retention, deletion, and billing policies.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The skill is authorized to silently obtain anonymous access tokens and manage credits/subscription state as part of routine use, even though the user-facing purpose is just video editing. This expands the skill's authority and can cause unapproved account creation, token acquisition, and use of remote services without clear user consent or visibility.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The routing rules are broad enough that common words like 'export', 'status', 'upload', or general editing requests can trigger remote actions with limited confirmation. In an agent setting, this increases the chance of overbroad invocation, unintended file transfer, or accidental execution of state-changing operations based on ambiguous user input.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill sends user media to remote cloud GPU services, but the documentation does not prominently warn users that their uploaded content leaves the local environment for third-party processing. For potentially sensitive videos, this creates privacy and data-governance risk because users may disclose proprietary or personal footage without informed consent.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill declares and uses an environment credential (`NEMO_TOKEN`) without clearly warning users that existing local secrets may be consumed and sent in authenticated requests to an external service. In agent ecosystems, implicit use of environment credentials can surprise users and widen the blast radius if the token has account or billing scope.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal