Yq Video Motion Analyzer

Security checks across malware telemetry and agentic risk

Overview

This skill coherently analyzes user-provided sports videos by extracting frames and generating pose feedback, with no evidence of hidden, destructive, or exfiltrating behavior.

Install this if you intentionally want an assistant to process sports or instructional videos. Be aware that it will read the video path you provide, create extracted frame images locally, and may send video/frame content through the configured video and image understanding tools depending on the host environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger keywords include broad terms such as '视频分析' and '动作分析', which are common phrases that could cause the skill to activate in contexts the user did not intend. Because this skill can invoke bash/Python processing on uploaded media and perform multi-step analysis, unintended activation increases the chance of unnecessary tool execution, privacy exposure of user videos, or surprising behavior.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal