tasteforge-video
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to execute local system commands using
python3 -m tasteforge,ffmpeg, andffprobe. These operations are restricted to the local workspace and are central to the skill's primary purpose of processing media metadata and generating edit timelines. - [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted data through various ingestion points including
workflow.json,media.json,answers.json, and local media files. To mitigate risks associated with processing external data, the skill implements a comprehensive validation contract: - Boundary Markers: Instructions enforce strict schema flags such as
provider_calls:0(integer only),dry_run:true,submit:false, andprovider_call_mode:"disabled"to prevent accidental execution of remote workflows. - Capability Inventory: Capabilities are limited to local command execution (
tasteforgepackage) and file writing (--out-dir) for timeline exports (EDL/FCPXML). - Sanitization: The skill mandates the rejection of non-numeric booleans (e.g.,
true/falsein numeric fields), the rejection of symbolic links and special files (FIFOs/devices), and mandatory SHA-256 integrity checks for all referenced artifacts to prevent tampering. - [SAFE]: The skill explicitly defines a 'fail-closed' security boundary that prohibits network interaction with external providers (like Fal) and forbids the reading of environment credentials such as
FAL_KEY.
Audit Metadata