skills/ericrisco/rsc-harness/ai-media/Gen Agent Trust Hub

ai-media

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes user-supplied narration scripts and creative goals to generate shell commands and API calls. While providing a structured workflow, the instructions lack guidance on sanitizing or escaping user input when it is interpolated into ffmpeg command arguments.
  • Ingestion points: Narration scripts and creative goal descriptions defined in SKILL.md and evals/cases.yaml.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the pipeline design.
  • Capability inventory: The skill directs the agent to generate shell scripts and execute API calls via elevenlabs and other media plugins.
  • Sanitization: No logic is provided to filter or escape user-provided strings during the assembly phase.
  • [SAFE]: The skill manages authentication tokens (e.g., ELEVENLABS_API_KEY) through standard environment variables, avoiding hardcoded secrets.
  • [SAFE]: Documentation links and asset sources target well-known technology organizations and trusted AI service providers.
  • [SAFE]: The provided verify.sh utility performs local linting of scripts and does not perform network operations or access privileged system resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — ai-media