Video Ai App

Security checks across malware telemetry and agentic risk

Overview

This skill is a cloud video-editing helper that sends user videos and prompts to NemoVideo, which is expected for its purpose but should be understood before use.

Install only if you are comfortable sending uploaded videos, prompts, and NemoVideo session/token data to nemovideo.ai for cloud processing. Avoid uploading confidential footage unless you trust the provider's privacy, retention, and account practices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill encourages users to upload raw video footage but does not prominently warn that their content is transmitted to a third-party remote processing service. Because videos often contain faces, voices, locations, screens, and other sensitive data, users may unknowingly disclose personal or confidential information to an external provider, creating a privacy and data-governance risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal