music-to-video
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns such as prompt injection, data exfiltration, or persistence mechanisms were detected. The orchestrator logic focuses on a structured multi-step video production workflow.
- [COMMAND_EXECUTION]: The skill uses
subprocess.runinscripts/analyze-beatgrid.pyto executeffmpeg. The implementation is secure as it avoidsshell=Trueand passes arguments as a structured list, preventing command injection. It also usesnpxto call thehyperframesCLI, which is consistent with the skill's stated purpose. - [EXTERNAL_DOWNLOADS]: The HTML templates reference standard JavaScript libraries (GSAP, Three.js) and fonts from well-known, trusted CDNs (jsDelivr and Google Fonts). These are recognized as safe external sources.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data including
audiomap.json,STORYBOARD.md, and user-supplied media. The author has implemented a robustcleanSvgsanitization function inreferences/templates/logo-split-lockup-pulse/index.htmlto strip active content (scripts, handlers) from user-provided SVG marks, effectively mitigating XSS risks in the generated output.
Audit Metadata