dbs-video-navigation

Pass

Audited by Gen Agent Trust Hub on Oct 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local binaries including ffmpeg, ffprobe, and swift (on macOS) through the subprocess module. These calls use argument lists rather than shell strings, which effectively mitigates command injection risks. These tools are strictly necessary for the skill's stated purpose of video probing, audio extraction, and rendering.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, user-provided subtitle files (SRT) and project configuration JSONs which could theoretically contain malicious instructions.
  • Ingestion points: scripts/navigation.py reads user-provided SRT files and project.json files.
  • Boundary markers: The agent instructions in SKILL.md explicitly state that user materials are data for analysis and must not be treated as instructions to expand permissions or call tools.
  • Capability inventory: The skill possesses the capability to execute video processing commands and write files to the local disk.
  • Sanitization: The script performs strict validation on input fields, including time formats (regex), JSON schema verification, and filename slugification to prevent path traversal or other filesystem issues.
  • [SAFE]: The skill demonstrates standard development practices for media processing tools. It uses dedicated configuration directories (~/.dbs/video-navigation), avoids hardcoded credentials, and does not perform unauthorized network communication. All dependencies listed are standard and well-known libraries.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 7, 2026, 06:53 AM