Music Video Clip

PassAudited by VirusTotal on May 11, 2026.

Findings (1)

The music-video-clip skill (SKILL.md) connects to a third-party API at mega-api-prod.nemovideo.ai to generate synced music videos. It is classified as suspicious due to instructions that direct the agent to 'process internally' tool calls received from a remote Server-Sent Events (SSE) stream, which could allow a compromised backend to trigger unauthorized actions on the host. Furthermore, the skill requires the agent to auto-detect its platform from the installation path for telemetry and manages authentication via the NEMO_TOKEN environment variable, representing a significant attack surface despite being aligned with the stated functionality.