editframe-api
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (media files, HTML compositions) through tools like
createRenderandtranscribeFile. This presents an attack surface where maliciously crafted input files or HTML could attempt to influence the agent's logic or output, especially when handling transcription results or composition metadata.- [COMMAND_EXECUTION]: The CLI component of the skill (@editframe/cli) performs local system operations including media probing viaffmpeg(editframe mux), local rendering, and asset syncing. While these are core features, they involve executing shell-level operations on user-provided file paths.- [EXTERNAL_DOWNLOADS]: The skill's primary function is to interact with Editframe's cloud infrastructure (editframe.com). It performs numerous network operations to upload media assets, submit rendering jobs, and download processed video files. These are considered safe as they target the well-known vendor's official service endpoints.
Audit Metadata