Video Maker Editor Free

Security checks across malware telemetry and agentic risk

Overview

This cloud video/text generator is purpose-aligned, but it automatically connects to NemoVideo and creates sessions/tokens with limited user-facing disclosure.

Install only if you are comfortable with NemoVideo receiving prompts, metadata, and uploaded files for cloud processing. Avoid using it with sensitive or private media unless you have reviewed the service terms and are willing to send that data to the backend.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation guidance uses generic phrases like "export," "download," and "upload," which are common in ordinary conversation and can cause the skill to trigger when the user did not clearly intend to use it. In a skill that can automatically authenticate to a third-party backend and process user media, over-broad activation increases the chance of unintended network actions and data transfer.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly instructs automatic connection to a remote service and anonymous token/session creation on first open, but does not clearly disclose that user prompts, metadata, and potentially uploaded media will be transmitted to a third-party backend. Because this skill handles large video/image files and cloud rendering, silent setup materially increases privacy and consent risk and can lead to unintended sharing of sensitive media.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal