Tiktok Video Generator Ai

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent cloud video-generation integration, but users should understand that uploaded media and prompts are sent to NemoVideo for processing.

Install only if you are comfortable sending selected photos, videos, audio, and prompt text to NemoVideo's cloud API. Keep NEMO_TOKEN private, avoid sensitive personal or proprietary media unless you trust the service, and review important actions such as exports or credit-spending steps before proceeding.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The routing table sends all unmatched requests to the SSE generation action, which can cause overly broad activation of remote processing for ambiguous prompts. In a skill that uploads media and sends free-form user instructions to a cloud backend, this increases the chance of unintended external requests, accidental media processing, and user actions being interpreted more expansively than expected.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill encourages users to provide videos and images but does not clearly warn that those files and prompts are sent to a third-party cloud service for processing. This can mislead users about data handling and create privacy risk, especially because uploaded media may contain sensitive personal, biometric, or proprietary information.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal