Back to skill

Security audit

Video Producer Tool Free

Security checks across malware telemetry and agentic risk

Overview

This short-video skill is purpose-aligned and disclosed, though users should notice that it can run local media commands and send scripts or prompts to external AI/TTS services.

Install only if you want an agent to generate short videos using local Node/Remotion/FFmpeg commands and external image/TTS APIs. Review the commands before running them, keep API keys scoped to the intended providers, and avoid using this skill for generic media conversion or unrelated audio/video editing unless you explicitly intend that workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger condition is phrased so broadly ('需要视频处理、音频编辑、媒体转换、配音生成时使用') that it can activate on many generic multimedia requests, even when the user did not intend to invoke this specific skill. In an agent environment with exec access, over-broad routing increases the chance of unnecessary command execution, unintended data handling, or use of external APIs on unrelated requests.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.