Back to skill

Security audit

RenderIO ffmpeg

Security checks across malware telemetry and agentic risk

Overview

This is a coherent RenderIO cloud media-processing skill with normal API key and upload privacy risks that users should understand.

Before installing, confirm the correct RenderIO API hostname from official RenderIO documentation, keep RENDERIO_API_KEY out of chats and source files, and only upload media you are allowed to send to a third-party cloud processor. Treat returned signed output URLs as sensitive access links.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill inconsistently documents and demonstrates two different API domains: it states the correct domain is `api.renderio.dev`, but multiple examples use `renderio.dev`. This can cause users or agents to send API keys and media to the wrong host, creating a risk of failed requests, credential disclosure, or unintended third-party transmission if the alternate domain is misconfigured or controlled differently.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill is explicitly designed to upload user-provided media URLs and local files to a third-party cloud processing service, but it does not prominently warn that data leaves the local environment. This creates a privacy and compliance risk because users may unknowingly transmit sensitive media, metadata, or copyrighted content to an external processor.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.