Back to skill

Security audit

Lh Video Gen Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill appears to match its video-generation purpose, with expected local command use and TTS/network considerations users should understand.

Install only if you are comfortable with the agent running local media commands and using TTS services. Do not put private or regulated text in scripts when cloud TTS is used, and only use --tts-command with commands you wrote or fully trust.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly supports video generation and network-backed TTS, but the documentation does not clearly warn that running it will write files to disk and may transmit user-provided script text to an external TTS service. This can cause unintended disclosure of sensitive content and unexpected side effects in agent environments where users may assume local-only processing.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The custom `--tts-command` feature allows arbitrary external command templates incorporating content such as `{text}`, `{output}`, `{voice}`, and `{rate}` without any safety guidance. In a tool with `exec` capability, this creates a command-injection and arbitrary command-execution risk if values are unsafely interpolated or if users paste untrusted command templates.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.