Back to skill

Security audit

Video

Security checks across malware telemetry and agentic risk

Overview

This is a video-processing skill whose file, command, and optional URL handling are disclosed and aligned with the stated media-editing purpose.

Install only if you are comfortable letting the agent read and write video files and run FFmpeg-style commands. Prefer local files or trusted URLs, and do not process copyrighted or sensitive media unless that is intentional.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The activation text is vague and expansive, describing generic video/audio/media capabilities in a way that could cause the skill to trigger for broadly scoped user requests beyond the user's intent. In an agent environment with read/exec/write tools, overbroad invocation increases the chance of unnecessary file access, command execution, or unintended handling of sensitive media inputs.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
Allowing 'content' to be a network link without a clear warning or consent model means the skill may fetch remote resources, exposing user IP/network metadata and potentially retrieving untrusted content. In combination with FFmpeg and exec capability, this raises SSRF-like, malicious media parsing, and unintended data-transfer risks if users do not understand that external fetching will occur.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.