ce-riffrec-feedback-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/analyze_riffrec_zip.py uses subprocess.run to call external system utilities including ffmpeg, ffprobe, and curl. Technical review confirms these calls are implemented using list-based arguments rather than shell strings, which effectively prevents shell command injection vulnerabilities. These utilities are used for media duration detection, frame extraction, and API interaction.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to process external feedback data (audio recordings, video, and notes). Transcripts generated from this data are interpolated into a template file (review-prompt.md) designed for follow-up analysis by an AI agent. This establishes a surface where malicious instructions hidden in the feedback could influence downstream agent behavior. The skill includes boundary markers to reduce this risk.
  • Ingestion points: Raw audio/video recordings and meeting notes processed in scripts/analyze_riffrec_zip.py and converted to transcripts.
  • Boundary markers: The skill uses XML-style tags (<video_frames> and <discussion_transcript>) in the generated review-prompt.md to isolate external content.
  • Capability inventory: The skill possesses file-writing capabilities and can execute local commands (ffmpeg, curl) through subprocesses.
  • Sanitization: Basic text normalization and length truncation are performed via compact_text, but no specific sanitization for markdown or prompt injection is present.
  • [EXTERNAL_DOWNLOADS]: The skill initiates network requests to https://api.openai.com/v1/audio/transcriptions to transcribe feedback audio. This involves sending data to a well-known service using standard API authentication via environment variables.
  • [SAFE_PRACTICES]: The Python script implements security best practices for file handling, such as using is_relative_to checks during ZIP extraction to mitigate ZipSlip vulnerabilities and validating that directories do not contain unexpected symlinks before copying files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:18 AM
Security Audit — agent-trust-hub — ce-riffrec-feedback-analysis