Tellers

Security checks across malware telemetry and agentic risk

Overview

This skill is a clearly disclosed Tellers video-creation integration, but users should be careful because it can upload media, spend credits, and make previews public.

Install only if you intend to use Tellers for video work. Verify the Homebrew tap, use a dedicated API key, avoid storing it where other tools can read it, upload only media you are allowed to send to Tellers, and explicitly confirm any action that spends credits, exports a project, or makes an asset public.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger description is broad enough to match many ordinary creative requests such as 'create a video' or 'add subtitles', which can cause the skill to activate when the user did not specifically intend to use tellers.ai. Because this skill can upload media, spend credits, export content, and alter sharing settings, over-broad invocation increases the chance of unintended external actions and data transfer.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill documents commands to make assets or projects publicly accessible and provides shareable preview URLs, but it does not require an explicit warning or confirmation about privacy consequences. If used on private footage, client work, or sensitive media, this can expose content to anyone with the link and may create an unintended public disclosure.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal