ai-avatar-video
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous examples for interacting with the
beltCLI tool to run AI applications. These commands are appropriately scoped to thebeltbinary in the skill's configuration, limiting potential for arbitrary command execution. - [EXTERNAL_DOWNLOADS]: The documentation includes links to external resources, such as installation scripts hosted on GitHub for the
inference-shorganization and media assets hosted oninference.sh. These downloads are transparently documented as part of the skill's setup and functionality. - [INDIRECT_PROMPT_INJECTION]: The skill processes external inputs like image and audio URLs within JSON payloads passed to CLI commands. While this defines an ingestion point for external data, the use of structured data and clear command boundaries significantly reduces the risk of accidental instruction obedience.
Audit Metadata