Back to skill

Security audit

Video Generation

Security checks across malware telemetry and agentic risk

Overview

This appears to be a content/video generation skill whose file-output behavior is expected, with minor usability and localization concerns but no evidence of malware or hidden data misuse.

Before installing, be aware that the skill may activate on common video-generation wording and may create output files. Ask the agent to confirm the target folder, filename, language or narration style, and overwrite behavior before generating final files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger words are very broad and include common phrases like '生成视频' and '创建视频', which can cause the skill to activate for ordinary user requests that may not have intended to invoke this specific capability. Over-broad activation increases the chance of unintended file-generation behavior or unexpected prompt-context injection into unrelated conversations.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs saving generated content as files and later states that content should be saved in the appropriate format, but it provides no user-facing confirmation, overwrite protection, or destination constraints. In an agent environment, this can lead to unexpected file creation, accidental overwriting of existing files, or silent persistence of generated artifacts without informed user consent.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The template hard-codes '标准普通话' for teaching narration, which embeds a linguistic/locale assumption without user choice or contextual justification. In a content-generation skill, this can systematically exclude users or audiences who need other languages, dialects, or accessibility-oriented voice options, leading to biased or inappropriate outputs at scale.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.