Back to skill

Security audit

Analyze Video By Qwen Free

Security checks across malware telemetry and agentic risk

Overview

This skill is for remote Qwen video analysis, but it needs review because local video content and a DashScope API key are handled with incomplete safeguards.

Review before installing if your videos may contain private, business, biometric, or regulated content. Use a dedicated DashScope API key with limited account exposure, avoid running the shown cat/grep command in a way that reveals the key, and confirm what data DashScope may retain or log before analyzing sensitive media.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill clearly relies on a remote DashScope multimodal API to analyze local video files, but the usage and summary text do not prominently warn users that the video content itself will be transmitted off-host for processing. This can mislead users into exposing sensitive local media under the assumption that analysis is purely local, creating a privacy and data-handling risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.