skills/cerredz/vidbyte-skills/insert/Gen Agent Trust Hub

insert

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data (URLs, local files, pasted text), creating an indirect prompt injection surface. The skill incorporates specific defenses to mitigate this risk.
  • Ingestion points: The agent reads source material from local paths, URLs, or direct user input as specified in SKILL.md.
  • Boundary markers: The instructions explicitly direct the agent to treat source text as untrusted data and ignore any commands embedded within it.
  • Capability inventory: The agent identifies key concepts to generate shell command snippets for knowledge retention.
  • Sanitization: The skill requires the agent to quote all shell arguments safely when generating output.
  • [COMMAND_EXECUTION]: The skill generates a vidbyte retain shell command derived from highlights in the source text. The agent is instructed to present this command for manual user review and execution rather than running it automatically, and it must ensure all arguments are safely quoted.
  • [EXTERNAL_DOWNLOADS]: The instructions reference the vidbyte-skills Node.js package as a recommended tool for the final handoff phase. This package is a resource associated with the author's tool ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 09:15 PM
Security Audit — agent-trust-hub — insert