Youtube Subtitle Video

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed cloud video-subtitling/editing skill, but users should know their prompts and supplied media may be sent to Nemovideo for processing.

Install only if you are comfortable using Nemovideo's cloud service. Avoid sending private videos, sensitive URLs, or confidential prompts unless you intend them to be processed by that third party, and keep NEMO_TOKEN private.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The suggested invocation phrases are very broad and overlap with normal conversational requests about videos, subtitles, or YouTube content. This can cause the skill to activate unintentionally and begin external API setup and session creation without a narrowly scoped user intent, increasing the chance of unintended data handling or network actions.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The routing table includes a catch-all rule that sends 'everything else' to the SSE action, effectively treating any non-matching input as an instruction to a remote backend. In this skill, that behavior is more dangerous because the SSE path can transmit arbitrary user text to an external service and trigger edits or workflow actions with little intent validation.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal