upload-media

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a Python script to handle the file upload process. This is a standard method for extending agent capabilities and the script's logic is visible and dedicated to the upload task.
  • [EXTERNAL_DOWNLOADS]: The skill communicates with legitimate domains associated with the service (jimeng.jianying.com and vod.bytedanceapi.com) using the standard requests library. No remote scripts or binary payloads are downloaded or executed.
  • [SAFE]: The skill requires authentication via a local configuration file provided by the user, which is a transparent method for managing session-based access to the Jimeng platform.
  • [DATA_EXFILTRATION]: The script reads files from the local filesystem solely for the purpose of uploading them to the designated VOD service as requested by the user, representing normal functionality rather than malicious exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 09:35 AM
Security Audit — agent-trust-hub — upload-media