chengfeng-check-videocut-updates

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes platform-native 'codex' CLI commands and vendor-specific Node.js scripts to manage the plugin lifecycle. It dynamically resolves the path to the update utility by querying the list of installed plugins on the system.
  • [PROMPT_INJECTION]: The skill defines an indirect injection surface by interpolating user-provided marketplace names and version identifiers into shell commands (File: SKILL.md). 1. Ingestion points: variables including '$marketplaceName', '$shownVersion', and checksum strings. 2. Boundary markers: none present in the command template. 3. Capability inventory: the skill can execute shell commands and Node.js scripts. 4. Sanitization: variables are wrapped in double quotes in the shell script.
  • [SAFE]: The external scripts and plugin resources used by this skill belong to the vendor 'Agentchengfeng'. The management operations are performed within the vendor's ecosystem and use the platform's standard update mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 03:50 PM
Security Audit — agent-trust-hub — chengfeng-check-videocut-updates