video-to-superprompt

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using ffprobe and ffmpeg to extract metadata and frames from video files. This involves direct interaction with the host system's shell.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from multiple sources, which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: Workflow step 1 in SKILL.md identifies several ingestion points, including local paths, uploaded files, URLs, browser-visible videos, article assets, and repository media.
  • Boundary markers: There are no clear delimiters or instructions provided to the agent to differentiate between the data being analyzed and the instructions it should follow, nor are there warnings to ignore instructions embedded within the source material.
  • Capability inventory: Across the scripts, the agent is granted the ability to run subprocesses (shell commands), read files from the workspace, and write files to the /tmp directory.
  • Sanitization: The instructions do not define any validation or sanitization steps for the input data before it is passed to the analysis tools or used to generate the final prompt.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 01:59 PM
Security Audit — agent-trust-hub — video-to-superprompt