Eb Video

Security checks across malware telemetry and agentic risk

Overview

This is a coherent cloud video-editing skill, but users should understand that their footage and editing instructions may be sent to the EB/Nemo video API for processing.

Install this only if you intend to use EB/Nemo's cloud service for video editing. Do not upload confidential, regulated, or private footage unless you trust that provider and are comfortable with the remote processing workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill’s invocation guidance is broad enough to activate on ordinary video-editing phrases, which can cause the agent to route routine user requests into this external cloud workflow without clear, deliberate user selection. In this skill, that matters because activation leads quickly into token acquisition, session creation, and potential upload of user media to a third-party service, increasing the risk of unintended data disclosure and surprise external actions.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill does not prominently and clearly disclose, before use, that user video files and prompts are sent to a remote cloud API for processing. Because the workflow includes automatic setup, anonymous token creation, session establishment, and upload to `mega-api-prod.nemovideo.ai`, users may unknowingly transmit potentially sensitive media to a third party, creating privacy, compliance, and consent risks.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal