Back to skill

Security audit

kreadoai-skills

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a real KreadoAI media tool, but it exposes high-risk avatar cloning and watermark/subtitle removal workflows without enough consent, rights, or data-sharing guardrails.

Install only if you are comfortable sending media and image URLs to KreadoAI and you will use it only on content and likenesses you own or have permission to modify. Avoid using it to remove watermarks or attribution from third-party media, and keep the API token out of logs, screenshots, shell history, and source control.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README explicitly advertises subtitle and watermark removal, which can facilitate copyright infringement, circumvention of attribution, and misuse of third-party media if users are not warned about authorization and legal constraints. In this skill context, the capability is directly promoted as a feature, so the absence of safety, rights, or acceptable-use guidance makes abuse more likely rather than being a purely neutral documentation issue.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly enables avatar cloning, talking-photo/video generation, and subtitle/watermark removal, which are high-risk media manipulation capabilities with obvious misuse potential such as impersonation, deceptive content creation, or stripping provenance and attribution markers. While this appears to be normal product functionality rather than overtly malicious behavior, documenting and routing these actions without any safety warning, consent requirement, or rights check increases the chance of unsafe or unauthorized use.

Missing User Warnings

Low
Confidence
80% confidence
Finding
The skill instructs users to supply an API token via environment variable or a credentials file but does not explicitly warn that the token is a secret that must not be exposed, logged, or committed. This is a lower-severity issue because the file itself does not leak the token, but weak secret-handling guidance can lead to accidental disclosure in terminals, shell history, screenshots, or source control.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The upload flow forwards a user-supplied image URL to KreadoAI's remote API without any in-tool disclosure that the referenced image will be transmitted to a third party for processing. Because this skill handles potentially sensitive biometric/photo data for avatar generation, users may unintentionally share personal images without clear consent or awareness, creating a real privacy and compliance risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.