media-use
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes several command-line tools to process media, including
ffmpeg,ffprobe,heygen,mflux-generate,codex,parakeet-mlx,ltx-2-mlx, andnpx hyperframes. Technical review of the implementation shows that it consistently usesexecFileSyncorspawnwith literal argument arrays rather than shell strings. This approach effectively mitigates risk of command injection by ensuring that user-provided inputs (like file paths or descriptions) are treated as data rather than executable shell code. - [EXTERNAL_DOWNLOADS]: To resolve assets, the skill fetches content from multiple remote services, including HeyGen's CDN,
svgl.app,jsdelivr.net,github.com, andduckduckgo.com. The download logic inscripts/lib/freeze.mjsincorporates several security safeguards: it validates that URLs are direct media links, enforces a 256MB file size limit to prevent disk exhaustion, and includes an SSRF guard that prevents the agent from making requests to local or private network addresses (e.g., localhost, internal IPs, cloud metadata endpoints). - [DATA_EXFILTRATION]: Usage statistics and telemetry are collected and sent to PostHog via
scripts/lib/telemetry.mjs. The analysis confirms that the telemetry is designed for project health monitoring and explicitly filters out sensitive information. Properties sent are restricted to coarse metadata such as media type, provider name, and resolution source, while specifically omitting PII, intent text, file names, or local file paths. Furthermore, users can opt out of tracking using environment variables likeDO_NOT_TRACKorHYPERFRAMES_NO_TELEMETRY. - [SAFE]: The skill demonstrates high code quality with robust error handling and adherence to least-privilege principles. Credentials for external APIs are managed through standard local configuration files or environment variables, and the included PostHog API key is a public write-only token intended for ingestion, posing no threat to the user environment.
Audit Metadata