Ai Cartoon Video Maker Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed cloud video-generation integration, but users should know their prompts and uploads go to NemoVideo’s remote service.

Install this only if you are comfortable sending prompts, uploaded files, URLs, and generated media state to NemoVideo’s remote servers. Avoid confidential, private, or rights-restricted media unless you trust that provider’s handling, and treat NEMO_TOKEN like a credential with possible credit or subscription limits.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The routing table sends all unmatched user input to the SSE generation action, which means arbitrary prompts and accidental inputs are forwarded to a remote backend by default. In a skill that accepts free-form text and files, this increases the chance of unintended data disclosure, surprising network actions, and abuse of paid/limited backend operations without explicit user intent.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill description encourages users to upload images or text but does not clearly warn that prompts, files, and derived media are transmitted to and processed by a third-party remote service. This can mislead users into sharing sensitive content without informed consent, especially because the skill markets itself as simple and frictionless.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal