Text To Video Create Ai

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only text-to-video skill that clearly relies on an external cloud video backend; the main risk is privacy, not hidden malicious behavior.

Install only if you are comfortable sending video prompts, text files, media, and generated project state to the nemovideo.ai cloud service. Avoid uploading sensitive or confidential material, and be aware that the skill may create an anonymous token/session automatically when first used.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The routing guidance is broad enough that ordinary user phrases like 'download', 'status', or generic editing requests can trigger networked actions without a strong confirmation boundary. In a skill that uploads content and performs remote rendering, ambiguous invocation increases the chance of unintended uploads, exports, or state-changing requests to the backend.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs automatic connection to a remote backend and automatic acquisition of an anonymous token on first open, before clearly informing the user that data and identifiers will be sent off-device. This creates a privacy and consent risk because simply opening the skill can initiate external network traffic and establish a session tied to a generated client identifier.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal