video-ad-specs

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs users to download installation instructions from an external GitHub repository (inference-sh/skills) and install a CLI tool from a non-trusted NPM organization (belt-sh/cli).
  • [COMMAND_EXECUTION]: The skill provides numerous shell command examples using the belt CLI to perform tasks such as logging into a remote service and executing AI model inference for video, audio, and caption generation.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation of video ads by interpolating user-provided prompts into model execution commands. This represents a potential surface for indirect injection if the input content is not properly sanitized before being passed to the underlying AI models.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 11:00 PM
Security Audit — agent-trust-hub — video-ad-specs