Jogg Ai Image To Video

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill uses a disclosed cloud video API for its stated image-to-video purpose, with privacy considerations around uploads and automatic session setup.

Install only if you are comfortable sending images, prompts, session data, and render jobs to the nemovideo.ai cloud service. Avoid sensitive personal, proprietary, or regulated media unless you trust that provider, and consider supplying your own NEMO_TOKEN if you do not want an anonymous token created automatically.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to automatically connect to a remote backend and, if no token exists, silently obtain an anonymous token from an external service. This creates undisclosed network and authentication behavior, may transmit identifying metadata, and can cause the agent to establish third-party sessions without explicit user consent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal