happyhorse

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and encourages the installation of the belt CLI and related skills from the belt-sh and inference-sh repositories.
  • [COMMAND_EXECUTION]: The skill executes the belt CLI tool to process video generation and editing commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted text prompts and media URLs (images and videos) for processing by AI models, which is an inherent surface for indirect prompt injection. 1. Ingestion points: input JSON parameters including prompt, first_frame, reference_images, and video in SKILL.md. 2. Boundary markers: None identified in the command examples. 3. Capability inventory: Execution of the belt CLI tool via shell commands. 4. Sanitization: No explicit validation or sanitization of user-provided content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:18 PM
Security Audit — agent-trust-hub — happyhorse