media-notes-publishing

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources that are not under the direct control of the user or the skill author.
  • Ingestion points: The scripts/acquire_subtitle.py script takes a user-provided <URL> (e.g., from Bilibili or YouTube) as input to fetch subtitles.
  • Boundary markers: The skill does not define explicit delimiters or instructions to the agent to ignore embedded commands within the fetched subtitle content.
  • Capability inventory: The skill includes capabilities to execute shell commands via python and node and perform file writes to the local filesystem (media-note/ and the site repository).
  • Sanitization: There is no evidence of sanitization or filtering of the extracted subtitle text before it is presented to the agent for note generation.
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute local scripts and commands to perform its tasks.
  • Evidence: Execution of python <skill>/scripts/acquire_subtitle.py and node scripts/publish-notes.mjs. These scripts interact with the local filesystem and external network resources to fetch media content and publish files to a target directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 09:27 AM
Security Audit — agent-trust-hub — media-notes-publishing