video-podcast-maker-nano
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructions that direct the agent to follow tool bindings in project configuration files (
AGENTS.md) without "scanning or second-guessing." This directive encourages the agent to suppress its own safety reasoning or validation of commands when they are sourced from these external files. - [COMMAND_EXECUTION]: The skill workflow involves invoking shell commands, specifically
ffmpegandffprobe, to verify audio durations and process video files. It also dynamically invokes other installed agent skills based on automated detection or configuration files. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by ingesting and processing untrusted data to influence its execution pipeline.
- Ingestion points: Untrusted data enters the context via web research (Step 1), project-level configuration files (
AGENTS.md/CLAUDE.md), and user-provided external assets. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat content from web research or project files as potentially untrusted data.
- Capability inventory: The skill has the capability to write to the file system, make network requests (web search and TTS APIs), and execute shell commands (
ffmpeg). - Sanitization: The skill implements a specific pronunciation check for TTS, but does not specify generic sanitization or escaping for data retrieved from web searches.
- [EXTERNAL_DOWNLOADS]: The skill facilitates the download of media assets and icons from several well-known services and repositories, including Pixabay, Pexels, unDraw, and official icon sets from Google and Microsoft.
Audit Metadata