heygen-avatar-video
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected during the analysis of this skill.
- [PROMPT_INJECTION]: The instructions explicitly guide the agent to respect safety filters, moderation policies, and consent requirements, reinforcing the underlying platform's safety boundaries.
- [CREDENTIALS_UNSAFE]: The documentation provides generic placeholders for API keys (e.g.,
X-Api-Key) and directs users to official documentation for authentication; no hardcoded or sensitive credentials were identified. - [EXTERNAL_DOWNLOADS]: All external URLs link to official HeyGen documentation, research, or policy pages. These are recognized as official resources for a well-known service.
- [DATA_EXFILTRATION]: No suspicious network requests or data exfiltration patterns were found. The skill describes standard API interaction patterns, including the use of webhooks for asynchronous processing.
- [REMOTE_CODE_EXECUTION]: The skill consists of instructional text and JSON schemas. It does not download, execute, or reference any external scripts or executable code.
Audit Metadata