Back to skill

Security audit

video-production-pipeline

Security checks across malware telemetry and agentic risk

Overview

This is a Markdown-only video production workflow with expected external-service and publishing references, but no executable behavior or hidden install actions.

Safe to install as an instruction-only workflow. Before using it with private scripts, unpublished media, private URLs, or production social accounts, confirm which agents and providers will receive the content, require explicit approval before publishing or scheduling, and decide where generated assets, logs, and caches will be stored or deleted.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
90% confidence
Finding
The skill explicitly supports external URL ingestion and orchestrates multiple agents and third-party services for research, generation, voice, and editing, but it does not warn users that supplied content may be transmitted to external providers or reused across pipeline stages. This can lead to unintended disclosure of sensitive data, privacy issues, and unexpected API/data-usage costs, especially because users may paste private URLs or proprietary source material into the workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.