videodb

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill does not contain any detected malicious patterns. It is a legitimate integration for the VideoDB platform.
  • [PROMPT_INJECTION]: No evidence of malicious prompt injection or override instructions. Prompt parameters within the SDK are used for intended generative and analytical tasks (e.g., scene description, image generation).
  • [DATA_EXFILTRATION]: No unauthorized data exfiltration detected. Network operations are restricted to official VideoDB service endpoints (videodb.io). Sensitive information such as VIDEO_DB_API_KEY is correctly handled using python-dotenv or environment variables.
  • [REMOTE_CODE_EXECUTION]: The skill utilizes the official videodb Python SDK. While the documentation mentions a local recorder binary for macOS desktop capture, this is a native component of the SDK's core functionality and is distributed through standard package management channels.
  • [COMMAND_EXECUTION]: All platform interactions are performed through Python script execution using the SDK. No instances of unsafe shell command construction or dynamic execution of untrusted input were found.
  • [PROMPT_INJECTION]: (Category 8: Indirect) The skill provides a surface for indirect prompt injection as it ingests untrusted data from video transcripts and screen content for LLM-based summarization. However, the risk is mitigated by the scope of the skill's capabilities and standard platform guardrails.
  • Ingestion points: Transcripts fetched via video.get_transcript_text() and screen activity descriptions in ws_listener.py.
  • Boundary markers: Missing in example interpolation code (f"...{transcript_text}").
  • Capability inventory: Subprocess execution for SDK tasks; file reading/writing in local state directories.
  • Sanitization: None explicitly demonstrated for text interpolation.
  • Note: This surface is inherent to the functional purpose of the tool and is assessed as SAFE in the context of this skill's implementation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 11:09 AM
Security Audit — agent-trust-hub — videodb