Back to skill

Security audit

Google Veo

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Google Veo video-generation helper that uses the inference.sh CLI, with normal installer and account-login risks for that kind of tool.

Install only if you trust inference.sh and its CLI distribution. Prefer manual checksum verification when practical, use the intended account for `infsh login`, and avoid putting confidential material in prompts or input files sent for video generation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger list includes broad terms such as "veo", "google video ai", and "google video generation" that could match general user requests not clearly intended for this specific skill. Overbroad activation can cause the agent to invoke this skill in unintended contexts, increasing the chance of misrouting user tasks to a shell-capable skill and creating unnecessary exposure to external CLI execution.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.