Back to skill

Security audit

kling

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent RunAPI/Kling video-generation guide, with third-party media upload and download behavior that fits its stated purpose.

Install only if you are comfortable sending prompts, request metadata, and any selected local media to RunAPI/Kling for processing. Use an API key intentionally, avoid sensitive source files unless you mean to upload them, and review generated download URLs before saving outputs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to place local media file paths into request.json, submit them to RunAPI/Kling, and download deliverables from external URLs, but it does not prominently warn the user that local files and request contents may be transmitted to third-party services. This creates a real risk of unintended disclosure of sensitive local media, embedded metadata, prompts, or other request data, especially because the skill is designed for file-handling and network transfers as a normal execution path.

VirusTotal

36/36 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.