video-comparer

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/compare.py uses subprocess.run to call ffmpeg and ffprobe. It follows security best practices by passing arguments as a list rather than a shell string, effectively preventing command injection. Additionally, it performs extensive input validation, including file existence, extension whitelisting, and size limit checks before execution.
  • [EXTERNAL_DOWNLOADS]: The assets/template.html file includes links to the img-comparison-slider library hosted on unpkg.com. This is a well-known CDN for frontend packages and is used here to provide the interactive UI in the generated report. This download occurs in the user's browser when viewing the report, not during the skill's execution on the agent's environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external video files and extracts metadata that is later displayed in an HTML report. While the script uses regular expressions to constrain some metadata fields (like codec names), the direct interpolation of data into the HTML template presents a theoretical, low-risk surface for Cross-Site Scripting (XSS) if a user were to analyze a maliciously crafted video file and then open the resulting report. The risk is minimized by the use of ffprobe which typically returns standardized output strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:06 AM
Security Audit — agent-trust-hub — video-comparer