Deepseek Video Generation Free

Security checks across malware telemetry and agentic risk

Overview

This is a cloud video-generation skill that openly sends prompts and media to a named API, with no hidden code or destructive behavior found.

Install only if you are comfortable sending prompts, images, videos, and generated project state to the listed third-party cloud API. Avoid uploading sensitive, private, or rights-restricted media unless you understand that service's privacy and retention practices, and expect generation or export actions to use credits.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The routing table sends 'Everything else' to the SSE action, which effectively grants the remote backend broad authority to process almost any unmatched user request. In a skill that proxies user input to an external service, this increases the chance of unintended data handling, unexpected remote actions, and misuse outside the advertised video-generation scope.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to upload local media files to a third-party API but does not provide a clear privacy notice, retention policy, or warning that user content will leave the local environment. This creates a real risk of unintentional disclosure of sensitive images, videos, metadata, or copyrighted material to an external service.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal