Video Editor With Ai Image

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed cloud video-editing skill that sends prompts and media to NemoVideo, with broad routing that users should treat carefully but no evidence of hidden, destructive, or deceptive behavior.

Install only if you are comfortable sending selected prompts, files, and editing instructions to NemoVideo's cloud service. Use a dedicated NEMO_TOKEN when possible, avoid confidential media unless you trust the service, and ask the agent to confirm before uploads, exports, or long-running edits when your intent is ambiguous.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The example invocation phrases are very broad and overlap with ordinary user conversation, making accidental activation or misrouting likely. In an agent skill that can upload media, create sessions, consume backend credits, and trigger remote processing, ambiguous invocation increases the chance of unintended external API actions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The routing rule sends "Everything else" to the SSE editing action, which effectively turns unclear or unrelated user input into backend-executed edit requests. Because the SSE path can cause remote state changes and prolonged processing, this catch-all behavior creates an unsafe default that may trigger unintended operations and resource consumption.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal