video-to-superprompt

Fail

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The technical inspection workflow in SKILL.md instructs the agent to execute shell commands (ffprobe and ffmpeg) to process video files. The agent is directed to use a $VIDEO variable, which is populated by user-supplied local paths or URLs, directly within shell command strings. This pattern is vulnerable to command injection (e.g., via shell metacharacters in the file path) as there are no instructions for the agent to validate or sanitize the input before execution.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by processing untrusted external data to generate complex build prompts. Ingestion points: User-provided local file paths, uploaded media, and external URLs identified in SKILL.md. Boundary markers: Absent; there are no instructions to the agent to treat video metadata or external content as untrusted or to ignore embedded instructions. Capability inventory: The agent has the ability to execute shell commands (ffprobe, ffmpeg, mkdir) and perform file system operations. Sanitization: Absent; the workflow does not include steps to filter or escape user-provided inputs before they are used in the technical analysis phase.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 16, 2026, 07:32 AM
Security Audit — agent-trust-hub — video-to-superprompt