Back to skill

Security audit

Product Ad Video

Security checks across malware telemetry and agentic risk

Overview

This skill gives coherent instructions for turning product images or footage into short ad videos using external Runware video models, with a privacy note users should consider before uploading media.

Install only if you are comfortable sending the selected product images or footage to external video-generation providers through Runware. Avoid confidential, regulated, or personally identifying media unless you have authorization and have checked the provider's retention, deletion, and consent requirements.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The examples instruct users to send source images and videos to third-party URLs and poll a remote service, but they do not include any warning about privacy, retention, consent, or sensitive-content handling. In a media-processing skill, users may upload proprietary product assets, unreleased campaign materials, or footage containing people, so omission of data-handling guidance can lead to accidental disclosure or non-compliant processing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.