video-editing
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of transcripts and raw recording metadata to generate structure plans and edit decision lists. This represents a potential surface where malicious content embedded in transcripts could attempt to influence the agent's logic.
- Ingestion points: Recording transcripts and metadata ingestion in SKILL.md.
- Boundary markers: None explicitly defined in the example prompts to distinguish transcript content from instructions.
- Capability inventory: The skill generates and executes FFmpeg shell commands, Bash scripts, and Remotion (React/Node.js) code.
- Sanitization: No explicit sanitization or validation of transcript content before interpolation into prompts.
- [DYNAMIC_EXECUTION]: The skill workflow involves 'scaffolding' code, where an LLM generates Remotion components and FFmpeg command sequences which are subsequently executed (
npx remotion render,bash cuts.sh). This dynamic generation and execution of scripts is inherent to the skill's primary purpose but is documented as a known capability. - [COMMAND_EXECUTION]: The skill relies extensively on local shell command execution for video processing, including complex FFmpeg pipelines for cutting, merging, and reframing footage (SKILL.md).
Audit Metadata