Free Text To Video Generator Ai

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed cloud text-to-video skill, with expected risks around sending prompts or files to NemoVideo for processing.

Install only if you are comfortable sending prompts, scripts, and uploaded files to NemoVideo’s cloud service. Do not upload confidential, regulated, or private documents unless you trust the provider and have permission, and keep NEMO_TOKEN private because it can affect session access or credits.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The routing rule sends essentially all unmatched user input to the SSE/video-generation path, which can cause unintended uploads, remote processing, or paid actions when the user did not clearly request them. In this skill, that is more dangerous because the default path talks to an external cloud backend and may consume credits or transmit user-provided content without sufficiently precise intent confirmation.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill encourages users to send text, scripts, and files to produce videos, but it does not clearly warn that this content is transmitted to a third-party cloud service for processing. That creates a privacy and data-handling risk, especially if users provide sensitive documents under the assumption processing is local or opaque cloud disclosure is not material.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal