Yt Music

Security checks across malware telemetry and agentic risk

Overview

This skill is a single instruction file for cloud-rendering YouTube music videos, and its network, token, upload, and session behavior matches that purpose.

Install only if you are comfortable sending media files, prompts, session data, and render metadata to NemoVideo cloud services. Treat NEMO_TOKEN as a secret, avoid uploading sensitive or unlicensed media, and keep the session open until exports finish.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs sending uploaded media files, messages, and session data to a third-party cloud API, but the user-facing description does not clearly disclose that their content will be transmitted off-platform for remote processing. This creates a privacy and consent risk, especially because users may upload personal or unpublished media under the assumption processing is local or otherwise implicit.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal