happyhorse
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied text and external media URLs (images and videos) as input for AI video generation models.
- Ingestion points:
prompt,reference_images, andvideoparameters used in thebelt app runcommands withinSKILL.md. - Boundary markers: No specific delimiters or instructions to ignore embedded commands are included in the prompt templates.
- Capability inventory: The skill's operations are restricted to the
beltCLI tool via theBashtool configuration. - Sanitization: Input validation or sanitization is not explicitly defined in the skill instructions.
- [EXTERNAL_DOWNLOADS]: The skill references and recommends the installation of dependencies from the
inference-shandbelt-shGitHub organizations, which provide the underlying infrastructure for the skill's functionality. - Evidence: Recommends
npx skills add belt-sh/cliand links to configuration files hosted atraw.githubusercontent.com/inference-sh/skills/.
Audit Metadata