Browser Free Hd

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed cloud video-processing skill that uploads user-selected media to the stated NemoVideo backend and does not include hidden code or local persistence.

Install this only if you are comfortable sending the videos, audio, images, prompts, and related project metadata you provide to NemoVideo for cloud processing. Use a dedicated or low-privilege NEMO_TOKEN where possible, avoid sensitive media unless you trust the provider's privacy and retention practices, and ask the agent to explain backend handling before uploading confidential content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs uploading user videos and sending request content to a third-party backend without clearly warning the user that their files and prompts leave the local environment. This creates a privacy and data-handling risk, especially for sensitive media, because users may assume 'browser-based' or 'without installing software' means processing is local or minimally shared.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
Hard-coding the session language to English without user choice can cause prompts or content to be interpreted incorrectly, which may expose user data to unnecessary retransmission, mistranslation, or processing errors. While not a severe exploit, it is a trust and data-handling weakness because the backend receives user content under assumptions the user did not approve.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal