Story Video Generator

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a purpose-aligned video generation and processing helper, with ordinary media-tool side effects but no evidence of deception or unsafe behavior.

Before installing, confirm where generated and temporary media files will be written, how much disk space large videos may use, and whether the agent will ask before installing FFmpeg or other dependencies. Use it for media-generation tasks, but avoid giving it broad unattended authority if you want tight control over local file creation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill description uses broad natural-language triggers such as requests for video stories, short videos, image-to-video, and text-to-video, which can overlap with many generic user intents. This can cause unintended activation of the skill and lead to unnecessary tool use, media generation, and file creation without the user explicitly selecting this workflow.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs the agent to install FFmpeg if unavailable, generate multiple intermediate and final files, and execute media-processing commands, but it does not require explicit user notice or consent about these side effects. In an agent environment, this creates risk of unauthorized system modification, resource consumption, and unexpected persistence of generated artifacts on disk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal