Product Video Cutter Online

Security checks across malware telemetry and agentic risk

Overview

This skill is a cloud video-editing helper that sends uploaded media and edit requests to NemoVideo, which is disclosed and aligned with its purpose.

Install only if you are comfortable sending product videos, images, audio, edit prompts, and timeline data to NemoVideo’s cloud service. Avoid confidential, regulated, or customer-sensitive footage unless you have reviewed the provider’s privacy and retention terms, and ask for confirmation before uploads or credit-consuming exports.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
Routing nearly all unmatched prompts to the SSE backend creates an overly broad execution surface where arbitrary user text is forwarded to a remote service. In this skill, that increases the chance of unintended actions, data disclosure to the third-party processor, or abuse of expensive editing/generation operations outside the narrow 'video cutter' expectation.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The introductory description encourages users to upload media without clearly warning that files and editing instructions are sent to remote processing services. This is dangerous because users may unknowingly transmit sensitive or proprietary product footage, audio, and prompts to a third party, creating privacy, confidentiality, and compliance risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal