Video Deep Research
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's requirements and instructions are coherent with a video-research plugin; it only uses an OAuth flow or an optional API token and will send queries to the declared VDR MCP server — no unrelated credentials, installs, or hidden code were found.
This skill appears to do what it claims, but it will send your queries and any provided artifact paths to the external VDR MCP server (https://mcp.videodeepresearch.com by default). If you use the CLI token (VDR_MCP_TOKEN) avoid storing it in shared shells and verify the token issuer. Be cautious when supplying an s3_path — artifacts stored there could contain sensitive data and may be accessed by the VDR service or anyone with access to that S3 location. Verify you trust the hostname and DeepVideoLab.ai before sending private data. Because OAuth is recommended, prefer the OAuth connector in Claude Desktop/Cowork to avoid handling raw tokens when possible.
SkillSpector
SkillSpector findings are pending for this release.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings
