jianying-inspect

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes the jianying Rust CLI to perform metadata probing and project inspections based on absolute file paths provided by the user.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from video project drafts and media metadata files. Ingestion points: Project drafts and media files processed through jianying project inspect and jianying media probe (references/workflow.md). Boundary markers: The skill mandates the use of the --json flag for CLI tool output to ensure structured data interpretation and provides explicit evidence levels for reporting (SKILL.md). Capability inventory: Tools are restricted to read-only diagnostic operations; the skill explicitly prohibits generating scripts or overwriting source drafts (SKILL.md). Sanitization: Structural integrity and reference consistency are verified using the jianying project verify command before results are delivered.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 11:56 PM
Security Audit — agent-trust-hub — jianying-inspect