video-editing
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous shell command templates for the agent to use, primarily involving FFmpeg for cutting, concatenating, and normalizing video and audio files, as well as Remotion for rendering compositions.
- [EXTERNAL_DOWNLOADS]: The workflow references and provides code for interacting with well-known services including ElevenLabs (api.elevenlabs.io) and fal.ai for generating voiceovers, sound effects, and images.
- [PROMPT_INJECTION]: An indirect prompt injection surface is present in the suggested workflow. 1. Ingestion points: In Layer 2, the skill instructs the agent to analyze external transcripts from long recordings to identify segments. 2. Boundary markers: The example prompt provided for this task does not include delimiters or instructions to ignore embedded commands within the transcript. 3. Capability inventory: The agent is tasked with generating FFmpeg shell commands based on the content of these transcripts. 4. Sanitization: The skill does not describe any validation or sanitization of the transcript content before it is used to parameterize shell commands.
Audit Metadata