Video Editor Instagram Ai

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed cloud video-editing skill that sends chosen videos and edit prompts to NemoVideo for processing, with no hidden executable code found.

Install only if you are comfortable sending videos, URLs, prompts, and generated project state to NemoVideo's cloud service. Avoid uploading private or sensitive media unless you trust that provider's handling of the data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The routing table sends all unmatched prompts to the SSE editing action, which means vague or unrelated user input may still be forwarded to the remote backend. In this skill, that increases the chance of unintended cloud processing, surprise data disclosure to a third party, and accidental invocation of editing operations without clear user intent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill does use a cloud backend and says it will 'handle the AI Instagram editing on cloud GPUs,' but the user-facing setup and workflow text does not clearly foreground that uploaded media is transferred to an external service for processing and session-based storage. For a media-editing skill handling potentially sensitive videos, insufficient disclosure can cause users to unknowingly send private content off-device.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal