videodb
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill relies on the official 'videodb' Python SDK and 'python-dotenv', which are standard, verifiable packages from known registries.\n- [SAFE]: Security best practices are followed for credential management; users are instructed to use environment variables or .env files, and the skill explicitly avoids reading or writing these keys itself.\n- [SAFE]: The background listener script ('scripts/ws_listener.py') isolates its state files in a private user directory (~/.local/state/videodb) and explicitly sets directory permissions to 0700 to prevent access by other users.\n- [SAFE]: Remote operations, such as transcoding and media generation, are performed server-side by the trusted vendor (VideoDB), minimizing local execution risk.\n- [SAFE]: No evidence of prompt injection, obfuscation, or persistence mechanisms (like shell profile modification) was found in any of the skill files.
Audit Metadata