media-content-distiller

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes several Python scripts (e.g., acquire_subtitle.py, token_registry.py) that act as wrappers for a Node.js CLI. These scripts use subprocess.call to execute the Node runtime. The implementation correctly uses list-based arguments rather than shell strings, effectively preventing command injection vulnerabilities.
  • [EXTERNAL_DOWNLOADS]: The Node.js implementation in lib/core.mjs uses the fetch API to communicate with api.bibigpt.co. These requests are used to retrieve subtitle data and account metadata from the service provider based on user-supplied media URLs.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes subtitle content from external media URLs (e.g., Bilibili, YouTube) or local JSON files. This data is provided to the agent for summarization and analysis tasks. While this is the intended functionality, it creates a surface where instructions embedded in external media content could potentially influence the agent's behavior.
  • [CREDENTIALS_UNSAFE]: The skill handles BibiGPT API tokens using a local registry file (accounts.json). It implements strong security measures, including automatic redaction of tokens from logs and metadata files, and enforcing restricted filesystem permissions (chmod 0600) on the registry file to prevent access by other users on the system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 09:27 AM
Security Audit — agent-trust-hub — media-content-distiller