Back to skill

Security audit

Visla AI Video Creation

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Visla video-generation helper that uses Visla credentials and uploads user-selected content to Visla as expected for its purpose.

Install only if you are comfortable sending the scripts, URLs, documents, images, audio, or video files you select to Visla for processing. Use dedicated Visla API credentials, do not upload confidential material unless your Visla account terms allow it, and deny access to the saved credentials file if you prefer to provide credentials per run.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill declares required environment variables and file usage in metadata and instructs reading local credential files and user-provided documents, but the static finding notes no explicit declared permissions for env, file_read, and network capabilities. This creates a permission-model mismatch that can reduce transparency and allow broader data access than a reviewer or user expects, especially because the skill also uploads local content and uses remote APIs.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The CLI sends user-provided scripts, ideas, URLs, and uploaded local files to Visla’s remote API as part of normal operation, but the referenced workflow does not provide an explicit warning or consent checkpoint about external data transmission. In a skill that may process local documents and media, this creates a genuine privacy and data-handling risk because users may unintentionally upload sensitive content to a third-party service.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.