Ai Karaoke Video Maker Free

Security checks across malware telemetry and agentic risk

Overview

This skill is an instruction-only karaoke video tool that clearly uses NemoVideo cloud processing for user-provided media, with no local executable code found.

Install only if you are comfortable sending selected songs, videos, lyrics, prompts, and a generated client identifier to NemoVideo for cloud processing. Keep NEMO_TOKEN private and avoid uploading confidential or unauthorized media.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The routing table sends nearly all unmatched user input to the remote SSE action, creating a broad catch-all path that can cause unintended transmission of prompts and file-processing requests to the backend. In a skill that handles user media and free-form instructions, this increases the chance of accidental remote actions, privacy surprises, and misuse of external services without sufficiently explicit user intent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to automatically connect to an external API and generate or reuse authentication tokens before doing anything else, but it does not require a clear user-facing warning or consent about media, prompts, and identifiers being sent off-platform. Because the skill accepts uploaded audio/video files, this creates a significant privacy and data-transfer risk, especially when users may expect local assistance rather than immediate remote processing.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal