Cine Cog

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only CellCog video-generation skill that clearly needs an API key and remote service use, with no hidden executable behavior found.

Install only if you are comfortable using CellCog, setting a CellCog API key, and sending creative prompts or referenced project material to that service. Avoid including secrets or confidential unreleased material unless CellCog’s terms and your account controls are acceptable, and monitor credit or billing usage for video jobs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
77% confidence
Finding
The skill requires a CELLCOG_API_KEY and encourages use of a remote service, but it does not clearly warn users about credential handling, external data transmission, or the sensitivity of prompts/files sent to the provider. In an agent setting, this can lead users to unknowingly transmit proprietary content or mishandle API secrets.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal