happyhorse

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied text and external media URLs (images and videos) as input for AI video generation models.
  • Ingestion points: prompt, reference_images, and video parameters used in the belt app run commands within SKILL.md.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are included in the prompt templates.
  • Capability inventory: The skill's operations are restricted to the belt CLI tool via the Bash tool configuration.
  • Sanitization: Input validation or sanitization is not explicitly defined in the skill instructions.
  • [EXTERNAL_DOWNLOADS]: The skill references and recommends the installation of dependencies from the inference-sh and belt-sh GitHub organizations, which provide the underlying infrastructure for the skill's functionality.
  • Evidence: Recommends npx skills add belt-sh/cli and links to configuration files hosted at raw.githubusercontent.com/inference-sh/skills/.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:32 AM
Security Audit — agent-trust-hub — happyhorse