promo-video

Fail

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: HIGHINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests local repository metadata to dynamically generate options for the user. While the resulting options are presented for user selection, the lack of sanitization on ingested repository content creates an attack surface. * Ingestion points: Analyzes repository history via git log --oneline -100 and reads the project README.md file. * Capability inventory: The skill possesses extensive capabilities including shell execution via Bash (npm, npx, ffmpeg, python), file writing, and network operations. * Sanitization: There is no evidence of escaping or filtering logic applied to strings retrieved from the repository before they are interpolated into the user-facing selection menu.
  • [COMMAND_EXECUTION]: The skill relies on complex shell command orchestration to manage the video production pipeline. * Evidence: Automated execution of npm install and npx commands for project setup and Remotion rendering. * Evidence: Extensive use of ffmpeg and ffprobe for audio mixing and metadata extraction. * Evidence: Execution of a local Python script (scripts/generate_voiceover.py) which manages voice synthesis and audio normalization.
  • [EXTERNAL_DOWNLOADS]: The skill fetches remote media assets and interacts with AI services. * Evidence: Downloads background music from well-known stock services including Pixabay and Bensound using curl. * Evidence: Transmits script text to the ElevenLabs API (api.elevenlabs.io) for text-to-speech generation.
Recommendations
  • HIGH: Downloads and executes remote code from: unknown (check file) - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 26, 2026, 11:05 PM
Security Audit — agent-trust-hub — promo-video