Free Video Generator In Ai

Security checks across malware telemetry and agentic risk

Overview

This is a coherent cloud video-generation skill, but users should know their prompts and uploaded media go to NemoVideo's remote service.

Install only if you are comfortable sending video prompts, uploaded files, URLs, edits, and generated outputs to NemoVideo's cloud backend. Avoid sensitive or confidential media unless you have reviewed the provider's privacy and retention terms, and prefer using a dedicated NEMO_TOKEN rather than a personal shared credential.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Low
Confidence
85% confidence
Finding
The skill is described as a video generator, but it also instructs the agent to autonomously acquire anonymous tokens and manage session/credit state against a third-party backend. That expands the trust boundary from simple content processing to account-like authentication behavior, which can cause silent network actions, unanticipated token issuance, and exposure of a user's environment-backed credentials to a remote service.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The catch-all rule routes essentially any unmatched user request to the SSE action, which forwards free-form user input to a remote backend. This broad trigger greatly increases the chance of unintended data exfiltration, prompt confusion, or execution of backend-side operations unrelated to the user's actual intent, especially because the backend is treated as an action engine for editing and export workflows.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill directs the agent to automatically connect to the backend on first use and, if no token exists, to silently obtain an anonymous token from a third-party API. Performing authentication and network activity without a clear prior warning or consent is dangerous because it can surprise users, create external accounts/tokens on their behalf, and transmit metadata before they understand the privacy and security implications.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal