render-myth-vs-fact

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes ffmpeg and ffprobe to concatenate video beats, mix audio, and extract media metadata. All subprocess calls use array-based arguments, ensuring safety against shell injection.
  • [EXTERNAL_DOWNLOADS]: The skill fetches web fonts from Google Fonts and utilizes the fal-client library to upload audio for transcription. These interactions are purpose-aligned with the skill's video generation features.
  • [REMOTE_CODE_EXECUTION]: Playwright is used to render local HTML and JavaScript templates in a headless browser to generate video frames. This execution is deterministic and operates on local skill resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 09:42 AM
Security Audit — agent-trust-hub — render-myth-vs-fact