Perchance Ai

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed cloud video-generation integration that sends prompts and uploaded media to a remote service, with no executable installer or hidden local behavior found.

Install only if you are comfortable sending your prompts and any uploaded media to nemovideo.ai for cloud processing. Avoid sensitive files, and set your own NEMO_TOKEN if you want more control over which account or token is used.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to automatically connect to a remote backend and, if no token is present, silently obtain an anonymous token and create a session on first open. This causes network activity and credential issuance without clear prior user consent, which can surprise users, create privacy concerns, and establish persistent remote state tied to user interaction.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal