Instagram Video Editor Desktop

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed cloud video editor that sends user-selected media and editing requests to NemoVideo, with privacy considerations but no evidence of hidden or destructive behavior.

Install only if you are comfortable sending selected videos, edit prompts, render metadata, and bearer-token authenticated requests to NemoVideo's cloud service. Avoid uploading confidential, biometric, private-location, or client-sensitive footage unless you accept the provider's privacy and retention risks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to upload video files to a third-party cloud processing API, but it does not clearly warn that potentially sensitive media will leave the local machine and be stored or processed remotely. Videos often contain faces, voices, location data, screens, documents, or other personal information, so the lack of an explicit privacy disclosure can lead users to share sensitive content without informed consent.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal