ai-short-drama

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions and scripts to install the dreamina CLI from the official Bytedance/Jianying domain (jimeng.jianying.com) using a shell pipe. Following the trust-scope rules, this reference to a well-known technology service is considered safe as it is a legitimate requirement for the drama production workflow.\n- [COMMAND_EXECUTION]: Automated Python scripts (scripts/甑成分镜图.py, scripts/甑成分集视频.py) use the subprocess module to wrap the dreamina CLI. The analysis shows that these commands are constructed using structured arguments rather than raw user input, and they avoid dangerous shell=True patterns, mitigating command injection risks.\n- [DATA_EXFILTRATION]: Network operations identified are limited to interactions with the dreamina media generation platform. No evidence of unauthorized sensitive data access (such as harvesting credentials from .ssh or .aws directories) or exfiltration to unknown third-party domains was found.\n- [SAFE]: The skill does not contain any signs of malicious prompt injection, hidden obfuscation, or unauthorized persistence mechanisms. It includes extensive documentation on failure modes, error handling, and security best practices for AI media production.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 04:54 AM
Security Audit — agent-trust-hub — ai-short-drama