muapi-video-edit
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided media URLs and text prompts which are then sent to an external API. This creates a potential surface for indirect prompt injection if the ingested data contains malicious instructions targeting the downstream AI model.
- Ingestion points: Media URLs (
--video-url,--image-url,--audio-url,--face-url) and text descriptions (--prompt) are processed byscripts/lipsync.shandscripts/video-effects.sh. - Boundary markers: The skill does not implement specific delimiters or warnings to the agent to treat external content as untrusted data.
- Capability inventory: The skill possesses the capability to perform network requests via
curland write configuration to a local.envfile. - Sanitization: In
scripts/video-effects.sh, text prompts are safely JSON-encoded using Python before being sent to the API, which helps prevent shell command injection but does not mitigate prompt-level injection. - [EXTERNAL_DOWNLOADS]: The scripts perform outbound network operations to the vendor's API at
api.muapi.aito submit processing tasks and retrieve results. - This communication is necessary for the primary function of the skill.
- [COMMAND_EXECUTION]: The skill uses shell scripts to orchestrate API calls and utilizes system utilities such as
curl,grep,sed, andpython3for data processing and communication.
Audit Metadata