video-comparer
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/compare.pyusessubprocess.runto callffmpegandffprobe. It follows security best practices by passing arguments as a list rather than a shell string, effectively preventing command injection. Additionally, it performs extensive input validation, including file existence, extension whitelisting, and size limit checks before execution. - [EXTERNAL_DOWNLOADS]: The
assets/template.htmlfile includes links to theimg-comparison-sliderlibrary hosted onunpkg.com. This is a well-known CDN for frontend packages and is used here to provide the interactive UI in the generated report. This download occurs in the user's browser when viewing the report, not during the skill's execution on the agent's environment. - [INDIRECT_PROMPT_INJECTION]: The skill processes external video files and extracts metadata that is later displayed in an HTML report. While the script uses regular expressions to constrain some metadata fields (like codec names), the direct interpolation of data into the HTML template presents a theoretical, low-risk surface for Cross-Site Scripting (XSS) if a user were to analyze a maliciously crafted video file and then open the resulting report. The risk is minimized by the use of
ffprobewhich typically returns standardized output strings.
Audit Metadata