minimax-hailuo-video
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: Employs
ffmpegandffprobefor rigorous media validation. Subprocess calls are strictly bounded by timeout and output capacity, using hardcoded argument lists to prevent shell injection. - [EXTERNAL_DOWNLOADS]: Fetches generated video artifacts from user-defined hosts. Implements advanced security controls including DNS pinning, mandatory TLS SNI validation, IP literal rejection, and exclusion of redirects to mitigate SSRF and MITM risks.
- [CREDENTIALS_UNSAFE]: Adheres to secure practices by retrieving API keys solely from environment variables. Ledger files and logs are designed to redact sensitive information, including Base64 media data and prompt content.
- [DATA_EXFILTRATION]: No unauthorized exfiltration observed. Network operations are confined to legitimate regional MiniMax API endpoints and reviewed download hosts, with no secondary exfiltration paths.
Audit Metadata