videodb
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources, including video URLs, YouTube links, and RTSP feeds. It extracts spoken transcripts and visual descriptions which are subsequently processed by an LLM via the
coll.generate_text()method. This creates a surface for indirect prompt injection where instructions embedded in the media content could influence the agent's logic. - Ingestion points: Untrusted data enters the context through
coll.upload(url=...),video.get_transcript_text(), andrtstream.start_transcript(). - Boundary markers: The documentation and scripts do not mandate the use of explicit delimiters or instructions to ignore embedded commands when processing extracted media text.
- Capability inventory: The skill has access to tools for file upload, video transcoding, stream generation, and arbitrary Python code execution via the
Bashtool. - Sanitization: No specific sanitization or filtering logic for processed transcript or visual data is presented in the skill's reference materials.
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
videodbandpython-dotenvPython packages from standard registries. These are necessary dependencies for the SDK's operation. - [COMMAND_EXECUTION]: The skill frequently uses the
Bash(python:*)tool to execute Python code snippets for media processing tasks. While this is the intended mode of operation for the SDK, it involves running shell-level commands to invoke the Python interpreter. - [DATA_EXFILTRATION]: By design, the skill uploads local video and audio files to the VideoDB cloud infrastructure for indexing and processing. Users should be aware that media data is transmitted to an external service provider.
Audit Metadata