Video Translate

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward HeyGen video translation skill; the main user consideration is that submitted videos or video identifiers are processed by HeyGen.

Install only if you are comfortable sending the referenced video content or HeyGen video IDs to HeyGen for cloud processing. Avoid confidential, regulated, or third-party media unless you have permission and have reviewed your organization’s and HeyGen’s data-handling requirements.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill sends user-supplied video URLs and associated media to HeyGen's external API, but it does not clearly warn users that their content leaves the local environment for third-party processing. This creates a real privacy and data-handling risk, especially if users provide sensitive, internal, or regulated video content under the assumption that processing is local or first-party only.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal