skills/editframe/skills/editframe-cli/Gen Agent Trust Hub

editframe-cli

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the @editframe/cli Node.js package and the whisper-timestamped Python package, which are necessary for video rendering and transcription features.- [DATA_EXPOSURE]: The tool manages API tokens for cloud rendering authentication via the EF_TOKEN environment variable or CLI flags. This usage is restricted to the vendor's own infrastructure.- [COMMAND_EXECUTION]: The skill documentation describes the execution of local processing tools including ffmpeg, vite, and npx to perform media manipulation and build operations.- [INDIRECT_PROMPT_INJECTION]: The render command provides a surface for data ingestion through the --data flag. This allows for dynamic interpolation of user-provided content into video compositions, which is a standard feature of the rendering engine.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 02:32 PM
Security Audit — agent-trust-hub — editframe-cli