Easy Avatar Video

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate cloud avatar-video skill, but it can route broad or ambiguous user text and uploaded files to a third-party video API without a clear confirmation step.

Install only if you intend to use Nemovideo-style cloud processing. Avoid confidential, regulated, client, or proprietary scripts and files unless you have permission and understand the provider’s privacy and retention terms. Require an explicit confirmation before uploading files or forwarding ambiguous prompts to the remote API.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill advertises and accepts very generic trigger phrases such as 'generate my text or script' and broadly routes 'everything else' into backend actions. This increases the chance of accidental invocation from ordinary conversation, which is risky here because the skill can initiate remote API setup, create sessions, and process user-provided content without a clearly intentional opt-in boundary.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The description encourages users to upload TXT, DOCX, PDF, and MP3 files to a cloud service but does not clearly warn that file contents and prompts are transmitted to a third-party remote API for processing. This can mislead users about where their data goes and creates privacy and consent risk, especially for sensitive documents or audio.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal