ai-short-drama
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install the official Dreamina CLI tool from Bytedance's official domain (jimeng.jianying.com). This is a well-known service, and the use of the installation script is a documented and standard procedure for obtaining the tool.\n- [COMMAND_EXECUTION]: Automated Python and Shell scripts within the skill execute the local dreamina CLI to automate creative tasks. These calls are implemented using Python's subprocess module with argument lists, which prevents shell injection and ensures secure command execution.\n- [SAFE]: Extensive analysis of the skill's 47 files confirms that all observed behaviors are consistent with its documented purpose. There is no evidence of sensitive data exposure, credential harvesting, or unauthorized persistence mechanisms. The skill demonstrates good security practices for local tool integration.
Audit Metadata