Back to skill

Security audit

在线视频转文字稿

Security checks across malware telemetry and agentic risk

Overview

This skill appears purpose-aligned: it fetches video subtitles and creates local DOCX transcript files, with ordinary caution needed around video links and local file output.

Install if you are comfortable with the agent running yt-dlp and Node locally, fetching subtitles from the video platform, installing the docx npm dependency, and writing transcript files. Use trusted video URLs and review output paths before sharing generated DOCX files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger criteria are broad enough that the skill may activate for many generic requests containing a video URL and transcript-related language, even when the user did not clearly consent to downloading and processing third-party content. Over-broad activation can cause unintended network access, external tool execution, and processing of untrusted URLs, increasing the chance of SSRF-like fetches, privacy issues, or misuse of local tooling.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.