happyhorse-video
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill documentation facilitates interaction with official API endpoints at
api.acedata.cloud, which is the primary domain of the author, acedatacloud. - [CREDENTIALS_UNSAFE]: The instructions recommend using
ACEDATACLOUD_API_TOKENstored in a.envfile. This represents a safe and standard implementation of environment-based secret management rather than hardcoding sensitive data. - [EXTERNAL_DOWNLOADS]: The skill mentions the installation of the
mcp-happyhorsepackage. This resource aligns with the author's naming conventions and is a legitimate vendor-owned tool. - [PROMPT_INJECTION]: As a video generation utility, the skill accepts user-provided prompts and media URLs that are passed to an external API (SKILL.md). While this creates an indirect prompt injection surface, it is a core functional requirement of the service and no specific malicious redirection or safety bypass instructions were detected. The ingestion of untrusted data is delimited by standard JSON structure in the provided
curlexamples.
Audit Metadata