produce-video

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on several Node.js scripts (bake-cuts.mjs, desilence.mjs, extract-frame.mjs) that execute system commands including ffmpeg, ffprobe, and auto-editor. These operations are fundamental to the skill's primary purpose of video editing. The scripts utilize spawnSync with arguments passed as an array, which is a security best practice to prevent shell command injection.
  • [EXTERNAL_DOWNLOADS]: The HTML overlay templates (e.g., CodeSnippet.html, Comparison.html) include a script tag fetching the GSAP library from cdn.jsdelivr.net. This is a well-known and trusted content delivery network used for legitimate web animation purposes within the video preview environment.
  • [SAFE]: The skill implements strict 'Gates' (e.g., P2 visual review, P4 overlay approval, P5 explicit-render gate) ensuring that the AI agent cannot perform permanent edits or high-resource rendering tasks without explicit user confirmation and visual inspection. All outputs are restricted to a user-defined output directory, preventing unauthorized file system pollution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 10:10 PM
Security Audit — agent-trust-hub — produce-video