videodb

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands to set up the environment (pip install), manage background processes for real-time media event listening (python scripts/ws_listener.py), and handle process cleanup (kill). These commands are standard for managing long-lived capture sessions and development dependencies as described in the documentation.
  • [EXTERNAL_DOWNLOADS]: The skill downloads the videodb Python SDK and interacts with the VideoDB cloud infrastructure (console.videodb.io). It also facilitates the ingestion of media from external sources such as public URLs and YouTube, which is consistent with its primary purpose of video ingestion and analysis.
  • [PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection because it ingests untrusted data from media (transcripts and visual descriptions) and processes it through LLM tools.
  • Ingestion points: Untrusted data enters the context via video.upload(url=...), coll.connect_rtstream(url=...), and local media file ingestion described in SKILL.md.
  • Boundary markers: The provided example prompts for LLM analysis and indexing do not explicitly use delimiters or instructions to ignore embedded commands within the media content.
  • Capability inventory: The agent has access to Bash(python:*) for code execution and network access via the SDK to VideoDB's processing APIs.
  • Sanitization: No explicit sanitization or filtering of transcribed text or visual scene descriptions is documented before they are interpolated into LLM prompts. However, this risk is intrinsic to AI-driven media analysis and is noted as a low-level concern due to the skill's specific intended use.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:43 AM
Security Audit — agent-trust-hub — videodb