video-maker-free

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a bridge to the NemoVideo AI platform, providing documentation and implementation examples for generating video content from various assets.
  • [DATA_EXFILTRATION]: The skill interacts with the external domain mega-api-prod.nemovideo.ai. This is identified as a vendor-controlled resource intended for API processing. The use of the $NEMO_TOKEN environment variable for authentication aligns with recommended security practices for secret management.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied prompts for video generation.
  • Ingestion points: The prompt field in the API request described in SKILL.md.
  • Capability inventory: Network operations via curl to the vendor API.
  • Boundary markers: The payload is encapsulated in a JSON object, but no specific prompt delimiters are used in the example.
  • Sanitization: Not specified in the documentation; however, the risk is minimal as the input is passed directly to the generation service.
  • [SAFE]: Configuration data is stored in a dedicated local path (~/.config/nemovideo/), which is standard behavior for maintaining user settings and does not indicate malicious file access.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 11:32 PM
Security Audit — agent-trust-hub — video-maker-free