Voiceover Creator

Security checks across malware telemetry and agentic risk

Overview

This is a coherent cloud voiceover tool whose main risk is that selected videos, scripts, URLs, and prompts are sent to NemoVideo for processing.

Install only if you are comfortable sending chosen videos, scripts, URLs, and editing prompts to NemoVideo's cloud service. Keep NEMO_TOKEN private, avoid confidential media unless you trust the provider's terms, and review generated edits before exporting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
Routing virtually all unmatched prompts to the SSE generation/editing backend creates an overbroad execution surface where unrelated or ambiguous user input is sent to a cloud service. In this skill, that increases the chance of unintended remote processing of user text or uploaded media and can trigger edits, state changes, or quota consumption without clear user intent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill encourages users to upload videos or scripts but does not clearly warn up front that prompts and media are transmitted to a third-party cloud backend for processing. Because the skill handles potentially sensitive user content, inadequate disclosure can lead to unintentional sharing of proprietary or personal media with an external service.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal