Video Generator Free Ai Online

Security checks across malware telemetry and agentic risk

Overview

This cloud video skill is not clearly malicious, but it can automatically connect to a remote backend and may send overly broad user input without clear confirmation.

Review before installing. Use this only if you are comfortable sending prompts, media, and session metadata to the NemoVideo backend. Prefer a limited-purpose NEMO_TOKEN, avoid private or sensitive media, and confirm that the agent asks before connecting, uploading, or generating.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The routing table sends all unmatched input to the SSE generation workflow, which can cause unintended network requests and forwarding of arbitrary user text to the remote backend. In a skill that uploads content and maintains remote sessions, this broad default increases the chance of accidental data transmission and prompt misrouting rather than enforcing explicit, least-privilege actions.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to automatically obtain a token and create a remote session on first open, without a clear user-facing notice or opt-in before contacting third-party infrastructure. That creates a privacy and consent issue because metadata and possibly user content may be transmitted off-platform before the user explicitly agrees.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal