Back to skill

Security audit

Loom Vision

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: it downloads a Loom video, extracts transcript and frames locally, and uses them for video review context.

Install only if you are comfortable with Loom videos being downloaded and stored locally as video, transcript, and image frames. Treat the output directory as sensitive if the Loom contains code, credentials, internal screens, or personal data, and delete it when no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill is configured to trigger automatically on pasted Loom URLs or broad requests about Loom video content, which can cause unintended invocation and automatic processing of shared media. In this context, invocation leads to downloading and storing video, transcript, and sampled frames locally, so an accidental trigger can expose more user data than expected and consume local resources.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README explicitly states that the skill downloads the source video, transcript, and sampled frames and stores them in an output directory, but it does not clearly warn users about local data retention or sensitivity of captured screen contents. Because Loom videos may contain source code, credentials, internal UI states, or personal data, retaining these artifacts on disk increases the risk of unintended disclosure through shared machines, backups, or later access by other processes.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs the agent to download a Loom video and persist the video, transcript, and sampled frames to local storage, but the user-facing description and usage guidance do not clearly warn about this data collection and retention behavior. Because Loom videos often contain sensitive screen content, credentials, internal code, or personal data, silent local persistence can create privacy and data-handling risks beyond what a user may reasonably expect from a simple 'review' or 'summarize' action.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.