Free Video Generator Link

Security checks across malware telemetry and agentic risk

Overview

This is a coherent cloud video-generation skill, but users should know their prompts and uploaded media go to NemoVideo’s API.

Install only if you are comfortable sending prompts, uploaded images/videos/audio, and session metadata to NemoVideo’s cloud service. Avoid sensitive or proprietary media unless you trust that service, and treat NEMO_TOKEN like a password.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The description is broad enough that ordinary user requests about text, images, or generating media could invoke this skill without clear user intent to use this specific third-party service. Because the skill immediately performs remote setup and may upload user-provided content to an external API, overbroad matching increases the chance of accidental activation and unintended data disclosure.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The fallback rule routes 'Everything else' to the SSE action, which effectively turns ambiguous prompts into remote processing requests. In this skill, that is more dangerous because SSE sends user messages to a cloud backend and can trigger stateful operations without a sufficiently specific match, creating a broad surface for accidental exfiltration or misuse.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill does not clearly warn users that their text, images, files, and related session data are transmitted to a third-party cloud rendering service. That omission undermines informed consent and is especially risky here because the workflow explicitly uploads content, creates remote sessions, and retains state tied to tokens and render jobs.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal