ai-video-production-master
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The script
scripts/cloud_i2v_batch.pysearches for and reads private SSH keys from standard locations in the user's home directory (e.g.,~/.ssh/id_ed25519,~/.ssh/id_rsa) to authenticate file transfers to cloud-provisioned GPU instances. - [COMMAND_EXECUTION]: Multiple scripts (
scripts/cloud_i2v_batch.py,scripts/motion_graphics_generator.py) execute shell commands usingsubprocess.runfor cloud management, file transfer viascp, and video processing withffmpegandImageMagick. Some commands are constructed using string interpolation of filenames, which could be exploited if filenames contain shell metacharacters. - [EXTERNAL_DOWNLOADS]: The
onstartscript inscripts/cloud_i2v_batch.pydownloads several large AI models from Hugging Face and installs Python packages (comfy-cli,httpx) on the provisioned cloud instance. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided text (motion prompts) and external image files. These inputs are interpolated into a JSON workflow for ComfyUI. While the JSON structure provides some boundaries, the text prompt is not sanitized before interpolation. (Ingestion points:
scripts/cloud_i2v_batch.py; Capability inventory: SSH, shell command execution, file system access; Boundary markers: JSON structure; Sanitization: Absent).
Audit Metadata