Back to skill

Security audit

alibabacloud-video-prompt-architect

Security checks across malware telemetry and agentic risk

Overview

This skill is a prompt-writing helper with no executable code; the main thing to notice is optional preference memory that should stay under user control.

Before installing, confirm that any saved preferences are handled by your agent's normal memory controls. Keep preference saving opt-in, reviewable, and clearable; otherwise the skill is proportionate for generating media prompts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Ssd 3

Medium
Confidence
91% confidence
Finding
The skill explicitly encourages remembering user preferences across uses without defining storage scope, retention period, consent, or data-minimization boundaries. That can lead to unnecessary persistence of behavioral data and cross-session profiling, which is a privacy/security concern even if the remembered items seem low sensitivity.

Ssd 3

Medium
Confidence
92% confidence
Finding
These interaction rules reinforce ongoing collection of repeated user behavior and proactive retention of preferences, again without clear consent or minimization controls. In aggregate, this increases the chance of persistent profiling and accidental retention of user data beyond what is necessary to generate prompts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.