Voiceover Ai Maker

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed cloud voiceover/video rendering skill, but users should understand that selected media and prompts are sent to NemoVideo for processing.

Install only if you are comfortable sending selected videos, audio, prompts, and session metadata to NemoVideo. Keep NEMO_TOKEN private, avoid confidential media unless you trust the provider, and confirm uploads, exports, and credit-consuming actions before running them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
Routing nearly all unmatched requests to the SSE action gives the remote backend broad discretion over user input, increasing the chance that unrelated or sensitive prompts are sent off-platform and interpreted as editing commands. In this skill, that risk is amplified because the SSE path can drive remote stateful operations and the backend responses are translated into actions, making overbroad invocation more dangerous than a simple chatbot fallback.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs the agent to automatically connect to a remote backend, upload media, and send prompts without clearly warning users that their files and instructions leave the local environment. This creates a real privacy and consent risk, especially because uploaded videos/audio may contain sensitive business, personal, or proprietary content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal