Product Video

Security checks across malware telemetry and agentic risk

Overview

This skill is a cloud product-video helper that uploads user-provided media to nemovideo.ai, which is expected for its stated purpose.

Install only if you are comfortable sending product images, videos, logos, prompts, and related metadata to nemovideo.ai for cloud processing. Avoid confidential or regulated media unless you have reviewed the provider’s privacy and retention terms, and use a scoped NEMO_TOKEN if you provide your own.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs the agent to upload user-provided media to a third-party cloud backend, but it does not require a clear user-facing disclosure or consent step before transmission. This can lead to inadvertent sharing of potentially sensitive product assets, branding materials, or embedded metadata with an external service, creating privacy and compliance risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal