Back to skill

Security audit

AI短视频工厂

Security checks across malware telemetry and agentic risk

Overview

This is a Markdown-only short-video workflow skill with broad trigger phrases but no hidden code, credential handling, persistence, or automatic publishing behavior.

Install if you want an agent workflow for automated short-video planning and production. Be aware it may activate on generic video-making requests, so confirm platform, length, and whether you actually want automated short-video generation before letting it proceed, especially for batch work or paid AI/media services.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list includes very broad everyday phrases such as '做视频', '生成视频', 'make video', and 'generate video', which can match many normal user requests outside the intended narrow workflow. This increases the chance of unintended skill activation, causing the agent to route users into an automated content-production flow they did not explicitly request.

Vague Triggers

High
Confidence
93% confidence
Finding
The markdown trigger table repeats ambiguous keywords across multiple categories, including generic terms like '做视频', 'create video', and platform names combined with '视频'. Repetition of broad triggers across the skill definition amplifies accidental invocation risk and makes the activation surface larger than necessary.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.