Back to skill

Security audit

hot-video-breakdown

Security checks across malware telemetry and agentic risk

Overview

This skill does what it claims: it downloads a user-provided video, transcribes it locally, and creates a local HTML analysis report, with the main risks disclosed.

Install only if you are comfortable with it downloading videos from links you provide, caching a local Whisper model, and writing transcripts/reports to the output directory. Avoid private or sensitive videos unless you control the output location, and provide cookies only when you intentionally want the tool to use that logged-in access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrase is broad enough to match ordinary user requests about video analysis, which can cause the skill to activate unexpectedly. Because this skill performs network downloads and local processing of user-supplied URLs, accidental invocation expands the attack surface and may lead to unintended fetching or processing of untrusted content.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.