ai-multimodal

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: In 'scripts/media_optimizer.py', the 'eval()' function is used to process the 'r_frame_rate' field extracted from media metadata via ffprobe. Because this data is derived from external, untrusted media files, it represents a risk where a crafted file could trigger arbitrary code execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data (audio, images, videos, and documents) and provide them to an AI model, creating a surface for indirect injection.
  • Ingestion points: Files are ingested in 'scripts/gemini_batch_process.py', 'scripts/document_converter.py', and 'scripts/media_optimizer.py'.
  • Boundary markers: None identified in the prompt templates used for extraction or analysis.
  • Capability inventory: The skill uses 'subprocess.run()' to execute ffmpeg commands in 'scripts/media_optimizer.py' and has file-writing capabilities to save results and generated assets.
  • Sanitization: There is no evidence of sanitization or filtering applied to the content extracted from external documents or media metadata before it is processed.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 08:36 PM
Security Audit — agent-trust-hub — ai-multimodal