chengfeng-subtitle

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Node.js scripts, specifically videocut-cli.cjs and ensure-running.cjs, which are contained within the plugin's internal directory. These tools are used for project inspection, transcript alignment, and subtitle file generation.
  • [SAFE]: No unauthorized data access, network exfiltration, or remote code execution patterns were identified. The skill adheres to a local-first processing model, utilizing project-specific JSON files and a predefined term dictionary. The discrepancy between the prompt description and the instruction set regarding re-transcription is noted as a functional variation rather than a security concern.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 01:08 AM
Security Audit — agent-trust-hub — chengfeng-subtitle