Back to skill

Security audit

NAIPAO SKILL

Security checks across malware telemetry and agentic risk

Overview

This skill is a product-video script helper with clear no-subtitle video handoff rules and no hidden executable behavior.

Reasonable to install for ecommerce video scripting. Before using video generation, be comfortable sharing product images and scripts with the chosen video tool, and double-check outputs if you require the strict no-subtitles/no-text-overlay behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The regeneration guidance includes 'more restrained text overlay,' which directly conflicts with the earlier default rule that forbids generated subtitles, captions, title cards, price stickers, and other on-screen text. This inconsistency can cause downstream agents or tools to reintroduce text overlays despite an explicit no-text policy, undermining compliance requirements and producing outputs that violate the user's constraints.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.