ai-media
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes user-supplied narration scripts and creative goals to generate shell commands and API calls. While providing a structured workflow, the instructions lack guidance on sanitizing or escaping user input when it is interpolated into ffmpeg command arguments.
- Ingestion points: Narration scripts and creative goal descriptions defined in SKILL.md and evals/cases.yaml.
- Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the pipeline design.
- Capability inventory: The skill directs the agent to generate shell scripts and execute API calls via elevenlabs and other media plugins.
- Sanitization: No logic is provided to filter or escape user-provided strings during the assembly phase.
- [SAFE]: The skill manages authentication tokens (e.g., ELEVENLABS_API_KEY) through standard environment variables, avoiding hardcoded secrets.
- [SAFE]: Documentation links and asset sources target well-known technology organizations and trusted AI service providers.
- [SAFE]: The provided verify.sh utility performs local linting of scripts and does not perform network operations or access privileged system resources.
Audit Metadata