Back to skill

Security audit

Scripting And Storyboarding

Security checks across malware telemetry and agentic risk

Overview

This is a content-planning skill for video scripting and storyboarding, with clear human approval boundaries and no executable install or runtime code.

Before installing, treat this as a planning aid: it can help draft AV scripts, shot lists, storyboard briefs, and production handoffs, but you should still review any claims, consent/likeness use, AI disclosures, and final publishing decisions yourself.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
(shot table or AI-previz briefs), the numbered shot list, the batch-shoot plan, the timing pass, and the
  footage-labeling map. The **human** shoots (or generates), judges every take/clip, and approves — the agent
  cannot see footage, judge a performance, or operate a camera, and never fabricates "that take works."
- **AI previz frames** follow the image rules (`flux`/`image-prompt`): no real-person likeness without
  consent, character bibles built on original/consented characters, AI-disclosure where the frames themselves
  get published.
- **Production integrity:** no staged-as-candid content (scripted actors posing as unaffiliated strangers =
Confidence
22% confidence
Finding
without consent

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.