ai-multimodal
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: In 'scripts/media_optimizer.py', the 'eval()' function is used to process the 'r_frame_rate' field extracted from media metadata via ffprobe. Because this data is derived from external, untrusted media files, it represents a risk where a crafted file could trigger arbitrary code execution.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data (audio, images, videos, and documents) and provide them to an AI model, creating a surface for indirect injection.
- Ingestion points: Files are ingested in 'scripts/gemini_batch_process.py', 'scripts/document_converter.py', and 'scripts/media_optimizer.py'.
- Boundary markers: None identified in the prompt templates used for extraction or analysis.
- Capability inventory: The skill uses 'subprocess.run()' to execute ffmpeg commands in 'scripts/media_optimizer.py' and has file-writing capabilities to save results and generated assets.
- Sanitization: There is no evidence of sanitization or filtering applied to the content extracted from external documents or media metadata before it is processed.
Audit Metadata