ai-avatar-video

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous examples for interacting with the belt CLI tool to run AI applications. These commands are appropriately scoped to the belt binary in the skill's configuration, limiting potential for arbitrary command execution.
  • [EXTERNAL_DOWNLOADS]: The documentation includes links to external resources, such as installation scripts hosted on GitHub for the inference-sh organization and media assets hosted on inference.sh. These downloads are transparently documented as part of the skill's setup and functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external inputs like image and audio URLs within JSON payloads passed to CLI commands. While this defines an ingestion point for external data, the use of structured data and clear command boundaries significantly reduces the risk of accidental instruction obedience.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 10:32 AM
Security Audit — agent-trust-hub — ai-avatar-video