consume-movie

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Python subprocess module in clips.py to execute ffmpeg for video processing and in book_context.py to interact with peer skills like dogpile and ingest-book. These executions are implemented using argument lists rather than shell strings, which effectively prevents shell injection vulnerabilities.
  • [EXTERNAL_DOWNLOADS]: The jellyfin_client.py module interacts with a Jellyfin media server API. While it defaults to localhost:8096, it is designed to communicate with the user's local media infrastructure. It correctly handles authentication by retrieving the JELLYFIN_API_KEY from the environment rather than hardcoding it.
  • [DATA_EXPOSURE]: The skill manages metadata, subtitle transcripts, and user notes within the dedicated directory ~/.pi/consume-movie/. It interacts with other local skills (e.g., /memory, /consume-book) to store and retrieve contextual insights, which is consistent with the intended functionality of the platform's multi-skill ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — consume-movie