explainer-video-guide

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches installation documentation from the inference-sh GitHub repository.- [EXTERNAL_DOWNLOADS]: Recommends installing the belt-sh/cli package and related skills using npx.- [INDIRECT_PROMPT_INJECTION]: The skill provides templates for generating media where user-supplied script text is interpolated into shell commands.
  • Ingestion points: Prompt fields in belt command examples within SKILL.md.
  • Boundary markers: Absent; inputs are passed directly as string values in JSON payloads.
  • Capability inventory: Execution of belt CLI commands via the Bash tool to perform remote media generation.
  • Sanitization: Not present; the skill does not suggest filtering or escaping user input before generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 11:00 PM
Security Audit — agent-trust-hub — explainer-video-guide