Ai Music Video Maker Free

Security checks across malware telemetry and agentic risk

Overview

This skill is an instruction-only cloud music-video integration, with expected external processing and no hidden install code or destructive behavior found.

Install only if you are comfortable sending your prompts and uploaded audio or media to NemoVideo's cloud service for rendering. Avoid uploading private, unreleased, copyrighted, or sensitive files unless you trust that provider's privacy and retention practices, and consider managing or rotating NEMO_TOKEN yourself.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill’s activation examples and routing language are broad enough to match ordinary requests about making music videos, which can cause the skill to trigger when a user did not clearly intend to invoke this third-party integration. That increases the chance of unexpected upload, external API use, and disclosure of user content to a remote service without sufficiently explicit consent.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs the agent to send audio files, prompts, and session data to a third-party cloud backend, but the user-facing description does not clearly warn about that data transfer up front. This is dangerous because users may share copyrighted, private, or sensitive media believing processing is local or native to the assistant, resulting in uninformed disclosure to an external service.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal