consume-movie
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Python
subprocessmodule inclips.pyto executeffmpegfor video processing and inbook_context.pyto interact with peer skills likedogpileandingest-book. These executions are implemented using argument lists rather than shell strings, which effectively prevents shell injection vulnerabilities. - [EXTERNAL_DOWNLOADS]: The
jellyfin_client.pymodule interacts with a Jellyfin media server API. While it defaults tolocalhost:8096, it is designed to communicate with the user's local media infrastructure. It correctly handles authentication by retrieving theJELLYFIN_API_KEYfrom the environment rather than hardcoding it. - [DATA_EXPOSURE]: The skill manages metadata, subtitle transcripts, and user notes within the dedicated directory
~/.pi/consume-movie/. It interacts with other local skills (e.g.,/memory,/consume-book) to store and retrieve contextual insights, which is consistent with the intended functionality of the platform's multi-skill ecosystem.
Audit Metadata