Back to skill

Security audit

video-storyboard-pro

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only creative storyboarding skill whose behavior matches its stated video planning purpose.

Installers should expect this skill to activate for broad requests about turning content into videos. It appears suitable for creative storyboard work, but users who only want generic video scripting may prefer a narrower skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation rules include broad, everyday phrases such as '把这个做成视频' and '转化为视频脚本', which can cause the skill to auto-load in many ordinary conversations that are only loosely related to storyboarding. Over-broad invocation increases the attack surface by injecting a large, high-authority instruction block into unrelated tasks, potentially overriding user intent or interfering with safer, more appropriate skills.

VirusTotal

51/51 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.