skills/0xsline/openchatcut/export/Gen Agent Trust Hub

export

Warn

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions that direct the agent to withhold technical implementation details (such as Remotion or storage internals) from the user unless debugging. This concealment pattern is used to prevent users from seeing the internal workings of the skill's execution environment.
  • [DATA_EXFILTRATION]: The agent is instructed to resolve and access the user's 'Downloads' directory (~/Downloads or %USERPROFILE%\Downloads) to inspect for existing files and Chrome download artifacts (.crdownload). This provides the agent with visibility into a sensitive user data directory.
  • [DATA_EXFILTRATION]: The skill facilitates the transition of local-only assets to cloud storage for rendering purposes, which involves moving user data to external services.
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute ffmpeg commands within a sandbox for standalone local-file video operations.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 29, 2026, 03:02 PM
Security Audit — agent-trust-hub — export