video-ad-specs

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references installation of the belt CLI tool from npx and provides links to its official GitHub documentation for setup instructions. These references target well-known infrastructure for the skill's purpose.
  • [COMMAND_EXECUTION]: The skill provides numerous Bash examples using the belt tool to generate videos and audio via remote inference services. These commands are templates for the user to generate content and do not contain malicious payloads, credential harvesting, or unauthorized system access.
  • [REMOTE_CODE_EXECUTION]: While the skill interacts with a remote API via the belt tool, the interaction is scoped to content generation (video, audio, TTS) and does not involve executing arbitrary code from untrusted sources on the host machine.
  • [DATA_EXFILTRATION]: No patterns of sensitive data access (e.g., SSH keys, environment variables) or exfiltration to third-party domains were detected. All network traffic is directed to the service provider's infrastructure for the stated purpose of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:18 PM
Security Audit — agent-trust-hub — video-ad-specs