ai-multimodal
Fail
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The script 'scripts/media_optimizer.py' uses the dangerous 'eval()' function to process frame rate data returned by 'ffprobe' ('info['fps'] = eval(stream.get('r_frame_rate', '0/1'))'). If a crafted media file causes 'ffprobe' to output a malicious string in its JSON metadata output, the script will execute that code with the permissions of the agent process.
- [COMMAND_EXECUTION]: The 'scripts/media_optimizer.py' script executes external shell commands ('ffmpeg' and 'ffprobe') using 'subprocess.run()'. While this is functional for media optimization, it serves as the entry point for the previously identified 'eval()' vulnerability.
- [DATA_EXFILTRATION]: Multiple scripts ('scripts/document_converter.py', 'scripts/gemini_batch_process.py', 'scripts/media_optimizer.py') implement an aggressive configuration discovery mechanism that traverses parent directories up to the '.claude/' global folder to locate and load '.env' files. This allows the skill to access sensitive credentials or environment data located outside its intended scope.
- [PROMPT_INJECTION]: The skill is vulnerable to Indirect Prompt Injection (Category 8) because it ingests untrusted media content and YouTube metadata without sanitization or boundary markers.
- Ingestion points: External media files (video, audio, PDF) and YouTube URLs processed in 'scripts/gemini_batch_process.py'.
- Boundary markers: Absent; the script interpolates user-provided prompts and media URI/bytes directly into the content list for the Gemini API.
- Capability inventory: Subprocess execution ('ffmpeg'), file system writes (to 'docs/assets'), and multimodal content generation.
- Sanitization: No validation or filtering is performed on media metadata or file content before submission to the AI model.
Recommendations
- AI detected serious security threats
Audit Metadata