media-content-distiller
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes several Python scripts (e.g.,
acquire_subtitle.py,token_registry.py) that act as wrappers for a Node.js CLI. These scripts usesubprocess.callto execute the Node runtime. The implementation correctly uses list-based arguments rather than shell strings, effectively preventing command injection vulnerabilities. - [EXTERNAL_DOWNLOADS]: The Node.js implementation in
lib/core.mjsuses thefetchAPI to communicate withapi.bibigpt.co. These requests are used to retrieve subtitle data and account metadata from the service provider based on user-supplied media URLs. - [INDIRECT_PROMPT_INJECTION]: The skill processes subtitle content from external media URLs (e.g., Bilibili, YouTube) or local JSON files. This data is provided to the agent for summarization and analysis tasks. While this is the intended functionality, it creates a surface where instructions embedded in external media content could potentially influence the agent's behavior.
- [CREDENTIALS_UNSAFE]: The skill handles BibiGPT API tokens using a local registry file (
accounts.json). It implements strong security measures, including automatic redaction of tokens from logs and metadata files, and enforcing restricted filesystem permissions (chmod 0600) on the registry file to prevent access by other users on the system.
Audit Metadata