happyhorse-video

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documentation facilitates interaction with official API endpoints at api.acedata.cloud, which is the primary domain of the author, acedatacloud.
  • [CREDENTIALS_UNSAFE]: The instructions recommend using ACEDATACLOUD_API_TOKEN stored in a .env file. This represents a safe and standard implementation of environment-based secret management rather than hardcoding sensitive data.
  • [EXTERNAL_DOWNLOADS]: The skill mentions the installation of the mcp-happyhorse package. This resource aligns with the author's naming conventions and is a legitimate vendor-owned tool.
  • [PROMPT_INJECTION]: As a video generation utility, the skill accepts user-provided prompts and media URLs that are passed to an external API (SKILL.md). While this creates an indirect prompt injection surface, it is a core functional requirement of the service and no specific malicious redirection or safety bypass instructions were detected. The ingestion of untrusted data is delimited by standard JSON structure in the provided curl examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 12:43 PM
Security Audit — agent-trust-hub — happyhorse-video