Ai Video Tutoring Video Maker

Security checks across static analysis, malware telemetry, and agentic risk

Overview

Prompt-injection indicators were detected in the submitted artifacts (unicode-control-chars); human review is required before treating this skill as clean.

This looks safe to install as an instruction-only skill based on the provided artifacts. Before using it, confirm you trust NemoVideo, use a limited token if possible, and avoid sending sensitive student data unless you have permission and understand the provider's privacy practices. ClawScan detected prompt-injection indicators (unicode-control-chars), so this skill requires review even though the model response was benign.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

If the token is misused, it could affect the user's NemoVideo account, quota, billing, or generated content.

Why it was flagged

The skill declares a NemoVideo credential. This is expected for a provider integration, but it gives the agent access to act through the user's NemoVideo account.

Skill content
Primary credential: NEMO_TOKEN
Recommendation

Use a dedicated or revocable NemoVideo token if available, and do not provide unrelated credentials.

What this means

Student essays, assignments, or tutoring material may be processed by the video provider and could contain private or regulated information.

Why it was flagged

The intended workflow can involve sending or rendering student work through the NemoVideo service. This is purpose-aligned, but educational and student content can be sensitive.

Skill content
NemoVideo: generates writing tutoring videos with screen-share commentary (the tutor reads the student's essay on screen, highlighting strengths and improvement areas in real time
Recommendation

Avoid including sensitive student identifiers or private records unless you have permission and understand the provider's retention and privacy terms.

What this means

Users have less external information to verify who maintains the skill or how NemoVideo should be configured.

Why it was flagged

The skill has limited provenance information, though there is no runnable package or install step in the provided artifacts.

Skill content
Source: unknown; Homepage: none; No install spec — this is an instruction-only skill.
Recommendation

Verify the provider and account setup independently before giving the skill a token or sensitive educational content.