Back to skill

Security audit

Luma

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Luma video workflow guide that may use the Luma API when connected, while keeping clip review, rights checks, and publishing under human control.

Before installing, understand that using this skill with a Luma connection can spend Luma/API credits and may send prompts, images, or footage to Luma. Use it only with content you have rights to use, verify current Luma plan terms in-app, and keep the human review step before anything is published.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
Plus-level plan (tier structures conflict across sources and two generations of plans coexist — **verify
  in-app**); **Luma retains a marketing/service license on your generations** (Enterprise for NDA/data-privacy);
  high-stakes → counsel (not legal advice).
- **Likeness + misinformation:** no real-person likeness (real or AI lookalike) without consent; **no photoreal
  fake-event footage targeting real people/companies** (misinformation + defamation — "satire" doesn't launder
  it); **AI-disclosure** where platform/region requires (EU AI Act; C2PA). **Sound:** no native audio — music/VO
  added in post with proper licenses. **Never fabricate** credit rates, tier terms, benchmarks, or capabilities
Confidence
22% confidence
Finding
without consent

VirusTotal

47/47 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.