Back to skill

Security audit

Reelyze - Instagram Reel, TikTok & Shorts Analyzer

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Reelyze API helper that clearly centers on sending public video URLs or content prompts to Reelyze for analysis and generation.

Install this only if you are comfortable sending public video URLs, content topics, and your Reelyze API key to Reelyze. Avoid submitting private drafts, confidential campaign plans, or sensitive creator strategy unless Reelyze's privacy and retention terms are acceptable, and keep REELYZE_BASE_URL pointed at a trusted endpoint.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill sends user-provided video URLs and generation inputs to the external Reelyze API, but the description does not clearly foreground that third-party transmission before use. This creates a meaningful privacy and consent risk because users may provide links, topics, or creator-strategy inputs without realizing they are being shared with an outside service.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.