Image To Video Canva

Security checks across malware telemetry and agentic risk

Overview

This skill appears purpose-built for cloud image-to-video generation, but it needs review because it can silently create third-party sessions and route broad user input to an external service.

Install only if you are comfortable with prompts and uploaded images being processed by NemoVideo's cloud service. Use a limited token, avoid sensitive or private media unless you trust the provider's data practices, and prefer explicit confirmation before uploads or remote processing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The catch-all routing rule sends 'Everything else' to the SSE backend, which can cause the skill to activate for overly broad or unrelated user requests. This increases the chance of unintended network transmission of user prompts to a third-party service and can trigger actions outside the user's reasonable expectations.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to automatically acquire a token and connect to an external API before handling user requests, while explicitly hiding technical details from the user. That creates a transparency and consent problem: user content may be transmitted off-platform immediately, including prompts or files, without clear notice or opt-in.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal