Back to skill

Security audit

one-detail-reads-person-video-gen

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed WeryAI video-generation skill that uses an API key and may send selected prompts or images to WeryAI, with no evidence of hidden or unrelated behavior.

Install only if you are comfortable using a WeryAI API key and sending prompts or chosen image inputs to WeryAI. Prefer public HTTPS image URLs; use local image paths only after confirming the file is non-sensitive, because the script can read and upload that file to WeryAI.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The implicit trigger prompts are broad and map to common social-video/content-creation requests, so this skill may activate when the user did not explicitly request it. In an agent setting, overbroad triggering can route benign requests into a specialized skill that encourages judging people from limited cues, increasing the chance of inappropriate profiling or unwanted behavior generation.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.