Video Maker Free Windows

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed cloud video-editing skill that sends selected media and prompts to NemoVideo, with no evidence of hidden local execution, destructive behavior, or unrelated data access.

Install only if you are comfortable sending selected videos, audio, images, editing prompts, and related timeline/session data to NemoVideo cloud services. Avoid sensitive or regulated media unless you trust the provider’s privacy, retention, and deletion practices, and watch credit or subscription limits despite the free-credit setup.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The routing table sends all unmatched requests to the SSE editing action, which can cause unintended remote operations for vague or unrelated prompts. In a skill that uploads media and drives a cloud backend, this broad trigger increases the chance of accidental data transmission or execution of expensive editing/render actions without clear user intent.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill does state later that processing is cloud-based, but the description and initial user-facing setup do not prominently warn that uploaded videos, audio, prompts, and derived timeline state are sent to a remote third-party backend. This creates a meaningful privacy and consent risk, especially for personal phone videos that may contain sensitive content or metadata.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal