Free Video Generator Bot

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real cloud video generator, but its instructions are broad enough that ordinary prompts or uploads could be sent to a third-party backend unintentionally.

Install only if you are comfortable with prompts and uploaded media being sent to mega-api-prod.nemovideo.ai. Use it deliberately for video tasks, avoid private or sensitive content, and protect or remove NEMO_TOKEN when you stop using the service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The startup text and example phrases are broad enough that ordinary conversation about generating prompts, images, exporting, or creating a video could unintentionally invoke the skill. Because this skill can automatically authenticate, create sessions, upload content, and trigger cloud-side processing, accidental activation can lead to unintended network calls, token issuance, credit consumption, and user data being sent to a third-party service.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The routing table includes a catch-all rule that sends 'Everything else' to the SSE editing/generation path, effectively treating most unmatched user input as an actionable command. In this skill, that path can cause remote backend interaction and content processing, so benign or unrelated user text may be forwarded off-platform and consume credits or modify session state without sufficiently explicit user intent.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal