music-to-video

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns such as prompt injection, data exfiltration, or persistence mechanisms were detected. The orchestrator logic focuses on a structured multi-step video production workflow.
  • [COMMAND_EXECUTION]: The skill uses subprocess.run in scripts/analyze-beatgrid.py to execute ffmpeg. The implementation is secure as it avoids shell=True and passes arguments as a structured list, preventing command injection. It also uses npx to call the hyperframes CLI, which is consistent with the skill's stated purpose.
  • [EXTERNAL_DOWNLOADS]: The HTML templates reference standard JavaScript libraries (GSAP, Three.js) and fonts from well-known, trusted CDNs (jsDelivr and Google Fonts). These are recognized as safe external sources.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data including audiomap.json, STORYBOARD.md, and user-supplied media. The author has implemented a robust cleanSvg sanitization function in references/templates/logo-split-lockup-pulse/index.html to strip active content (scripts, handlers) from user-provided SVG marks, effectively mitigating XSS risks in the generated output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — music-to-video