video-podcast-maker-lite

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads background music tracks from Pixabay's official content delivery network. As Pixabay is a well-known service for stock media, these downloads are considered standard functionality for a content creation skill.
  • [COMMAND_EXECUTION]: The skill executes shell commands for media processing, including ffmpeg for audio/video mixing and ffprobe for duration detection. It also utilizes npx remotion for rendering video frames. These commands are essential to the skill's primary purpose and do not involve untrusted code execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied topics to generate narration scripts, which creates a potential surface for indirect injection.
  • Ingestion points: The agent writes the podcast.txt script based on user input (SKILL.md Step 1).
  • Boundary markers: Narration segments are clearly delimited using [SECTION:name|label] markers (SKILL.md Step 1).
  • Capability inventory: The skill possesses the capability to execute shell commands (ffmpeg, remotion) and interact with the Azure TTS API.
  • Sanitization: The scripts/tts.py script escapes HTML special characters (&, <, >) before building SSML. Furthermore, the workflow enforces mandatory human review gates after script generation and before final rendering to mitigate automated exploitation.
  • [SAFE]: No patterns of obfuscation, credential exfiltration, persistence, or privilege escalation were found. Stated functionality matches the implemented code and instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:31 AM
Security Audit — agent-trust-hub — video-podcast-maker-lite