ai-video-production-master

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The script scripts/cloud_i2v_batch.py searches for and reads private SSH keys from standard locations in the user's home directory (e.g., ~/.ssh/id_ed25519, ~/.ssh/id_rsa) to authenticate file transfers to cloud-provisioned GPU instances.
  • [COMMAND_EXECUTION]: Multiple scripts (scripts/cloud_i2v_batch.py, scripts/motion_graphics_generator.py) execute shell commands using subprocess.run for cloud management, file transfer via scp, and video processing with ffmpeg and ImageMagick. Some commands are constructed using string interpolation of filenames, which could be exploited if filenames contain shell metacharacters.
  • [EXTERNAL_DOWNLOADS]: The onstart script in scripts/cloud_i2v_batch.py downloads several large AI models from Hugging Face and installs Python packages (comfy-cli, httpx) on the provisioned cloud instance.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided text (motion prompts) and external image files. These inputs are interpolated into a JSON workflow for ComfyUI. While the JSON structure provides some boundaries, the text prompt is not sanitized before interpolation. (Ingestion points: scripts/cloud_i2v_batch.py; Capability inventory: SSH, shell command execution, file system access; Boundary markers: JSON structure; Sanitization: Absent).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 03:01 PM
Security Audit — agent-trust-hub — ai-video-production-master