chengfeng-finish-talking-head

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell scripts and Node.js to automate video production tasks, such as preflight checks and project state management via ensure-runtime.cjs and videocut-cli.cjs.
  • [EXTERNAL_DOWNLOADS]: The runtime preflight includes an automated dependency installation step (--install-if-missing) to ensure required video processing binaries are available.
  • [PROMPT_INJECTION]: The skill manages an indirect prompt injection surface related to processing subtitle data and user requirements. Ingestion points: Ingests content from subtitles.srt and project configuration metadata. Boundary markers: Implements structured workflow transitions with manual user review views for storyboards and animations. Capability inventory: Accesses local file artifacts and executes production CLI tools scoped to the project directory. Sanitization: Uses product-level verification and state readback to validate artifact integrity.
  • [SAFE]: Utilizes trusted, well-known animation libraries GSAP (v3.15.0) and Rough.js for SVG rendering, and sources interface icons from established providers like Lucide and LobeHub.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 12:28 PM
Security Audit — agent-trust-hub — chengfeng-finish-talking-head