produce-video
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on several Node.js scripts (
bake-cuts.mjs,desilence.mjs,extract-frame.mjs) that execute system commands includingffmpeg,ffprobe, andauto-editor. These operations are fundamental to the skill's primary purpose of video editing. The scripts utilizespawnSyncwith arguments passed as an array, which is a security best practice to prevent shell command injection. - [EXTERNAL_DOWNLOADS]: The HTML overlay templates (e.g.,
CodeSnippet.html,Comparison.html) include a script tag fetching the GSAP library fromcdn.jsdelivr.net. This is a well-known and trusted content delivery network used for legitimate web animation purposes within the video preview environment. - [SAFE]: The skill implements strict 'Gates' (e.g., P2 visual review, P4 overlay approval, P5 explicit-render gate) ensuring that the AI agent cannot perform permanent edits or high-resource rendering tasks without explicit user confirmation and visual inspection. All outputs are restricted to a user-defined output directory, preventing unauthorized file system pollution.
Audit Metadata