Back to skill

Security audit

视频帧提取-免费版

Security checks across malware telemetry and agentic risk

Overview

This skill is a local video-frame extraction guide that uses ffmpeg, with one overly broad trigger statement but no evidence of hidden persistence, credential access, exfiltration, or destructive behavior.

Before installing, treat this as a local ffmpeg helper and use it only for video frame or thumbnail extraction. Be cautious if an agent tries to apply it to unrelated audio editing, conversion, dubbing, network callbacks, or bulk media workflows, because those are not clearly supported by this free skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
82% confidence
Finding
An overly broad trigger condition can cause an agent to invoke this skill for unrelated tasks, increasing the chance that user-controlled input gets funneled into exec-enabled workflows outside the intended scope. In a skill that advertises read/exec/write tooling and shell-based ffmpeg usage, poor scoping materially raises misuse risk even if no single payload is shown here.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.