No Login Video Editor Ai

Security checks across malware telemetry and agentic risk

Overview

This is a cloud video-editing skill whose network use and media uploads fit its stated purpose, though users should understand that uploaded media leaves their device.

Install only if you are comfortable sending selected videos, images, audio, media URLs, and editing prompts to NemoVideo’s cloud service. Avoid private screen recordings or sensitive footage unless you trust that provider, and protect any NEMO_TOKEN you configure.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The routing table sends all unmatched prompts to the SSE editing action, which can cause unrelated user requests to be forwarded to the remote backend. In a skill that uploads media and sends free-form prompts to a cloud service, this increases the chance of unintended data disclosure, surprising external actions, and misuse when user input is ambiguous or off-topic.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill encourages users to send video clips for processing but does not clearly warn, at the point of use, that files and prompts are transmitted to a third-party cloud backend. Because videos may contain faces, voices, screens, documents, or other sensitive content, this omission undermines informed consent and can lead to inadvertent exposure of private data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal