Back to skill

Security audit

视频文案智能提取大师

Security checks across malware telemetry and agentic risk

Overview

The skill performs its advertised video-to-text function, but users should review it because it uploads potentially sensitive videos to third-party infrastructure while making strong retention and privacy claims that the artifact cannot substantiate and partly contradicts.

Install only if you are comfortable sending the selected video, prompt, token, and task metadata to the GuaiKei service and its presigned storage endpoint. Treat the deletion and non-retention claims as unverified from this artifact, and avoid confidential meetings, interviews, customer data, or unreleased business media unless you have separate contractual or policy assurance from the provider.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The README makes strong privacy and deletion guarantees for uploaded video files, but this file provides no verifiable implementation details or evidence that such controls actually exist. In a skill that handles potentially sensitive meeting recordings, interviews, and enterprise media, unsubstantiated deletion/non-retention claims can mislead users into uploading confidential material under false assumptions.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The documentation says source videos are automatically destroyed after task completion, yet later instructs users to reuse a historical task ID without re-uploading the video. That creates an internal inconsistency suggesting some task artifacts, derived content, or source references persist longer than claimed, which is dangerous because users may rely on stronger deletion guarantees than the system actually provides.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The comment makes a strong privacy and data-retention promise ('automatically deleted after conversion') for uploaded videos, but this function implements only upload behavior and no deletion or lifecycle enforcement. In a video-to-text skill that handles potentially sensitive user media, such a mismatch can mislead operators and users into assuming data is ephemeral when it may persist indefinitely in object storage.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The package description defines a very broad activation scope across many loosely related requests such as transcription, summarization, copywriting, translation, meeting notes, and content analysis. In an agentic environment, this can cause the skill to trigger for ambiguous prompts and process sensitive user content or external links when a narrower, more appropriate skill should have been selected.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.