Ai Image To Video App

Security checks across malware telemetry and agentic risk

Overview

This skill is a cloud image-to-video helper whose API use matches its stated purpose, but users should understand that media and prompts are sent to NemoVideo.

Install only if you are comfortable sending images, prompts, and render-session metadata to NemoVideo’s cloud API. Avoid uploading sensitive personal photos, private documents, or confidential business media unless you trust that provider and understand its privacy and retention practices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The routing table sends 'Everything else' to the SSE action, which effectively captures nearly any unmatched user prompt and forwards it to the third-party backend. That broad fallback increases the chance of unintended invocation, accidental data disclosure, and user requests being processed by a remote service without sufficiently explicit scoping or confirmation.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill encourages users to send images and automatically connects to a cloud processing API, but it does not prominently warn that files and prompts will be transmitted to an external service. For a media-processing skill handling user-uploaded images, this creates a real privacy and consent risk, especially when photos may contain personal, biometric, or sensitive content.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal