Video Generator Online

Security checks across malware telemetry and agentic risk

Overview

This skill is a cloud video-generation connector that sends prompts and media to Nemo Video as part of its disclosed purpose, with privacy and credit-use considerations but no hidden or destructive behavior found.

Install this only if you are comfortable sending video prompts, uploaded images, audio, and video files to mega-api-prod.nemovideo.ai for cloud processing. Avoid confidential or regulated media unless you trust that provider's retention and privacy practices, and watch credit or subscription usage when exporting videos.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill encourages users to upload files and prompts to a third-party cloud API, but it does not clearly warn that user content, media, and text instructions are transmitted off-platform. This creates a real privacy and data-handling risk because users may disclose sensitive images, videos, or business content without informed consent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal