ingest-movie
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of subprocess calls to execute external binaries (
ffmpeg,whisper) and orchestrate other local skills (dogpile,ops-nzbgeek,agent-inbox,scillm,memory). While it implements path sanitization inutils.pyand uses list-based arguments to mitigate shell injection, the high volume of external tool orchestration increases the overall attack surface.\n- [COMMAND_EXECUTION]: Intaxonomy.py, the skill utilizesimportlib.utilto dynamically load thecommon_taxonomymodule from a computed relative path outside its directory. This dynamic loading pattern is a security concern as it could be exploited to load and execute unauthorized code if the directory structure is compromised.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting and parsing untrusted subtitle data (.srtfiles).\n - Ingestion points: Untrusted data enters the agent context through
scenes.py(parse_subtitle_file) andtranscribe.py(resolve_subtitle_file).\n - Boundary markers: Absent; extracted subtitle text and tags are stored in JSON manifests without specific delimiters or instructions for the LLM to ignore embedded commands.\n
- Capability inventory: The skill possesses significant capabilities, including media extraction via
ffmpeginextract.py, transcription viawhisperintranscribe.py, and network operations for movie acquisition inradarr.py.\n - Sanitization: Absent; the skill does not perform sanitization or filtering of the text content extracted from subtitles before processing it.\n- [EXTERNAL_DOWNLOADS]: The skill interacts with remote services (NZBGeek, Radarr) and uses the
subliminallibrary insubs.pyto search for and download subtitle files from various third-party providers.
Audit Metadata