chanjing-digital-human

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: Authentication tokens are stored in ~/.chanjing/credentials, which is the standard local configuration path for the Chanjing CLI and is used only for authorized API requests.
  • [COMMAND_EXECUTION]: The skill uses the framevideo CLI (via npx) to perform authentication checks, model listing, and asset management tasks.
  • [EXTERNAL_DOWNLOADS]: Media assets like digital-human videos, images, and audio are fetched from the vendor's remote servers and saved to the local assets/ directory.
  • [PROMPT_INJECTION]: The skill ingests metadata and status messages from the Chanjing API (Ingestion points: SKILL.md, references/ai-creation.md). There are no specific boundary markers or sanitization procedures described for this data. The skill possesses file-writing and CLI-execution capabilities (Capability inventory: writeFile, npx framevideo).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 08:52 AM
Security Audit — agent-trust-hub — chanjing-digital-human