learn-movie
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes the
ffmpegsystem utility viasubprocess.runto perform scene detection and keyframe extraction from video files. It also executes scripts from other local skills (scillm/run.shandmemory/run.sh) to perform analysis and persistence tasks. - [PROMPT_INJECTION]: User-provided strings from the
--directorcommand-line option are interpolated directly into the instructions sent to the Vision-Language Model (VLM). This represents a direct prompt injection surface where a user could manipulate the model's analysis output. - [PROMPT_INJECTION]: The skill processes external video content and parses the resulting VLM analysis into structured memory. This introduces an indirect prompt injection surface, as adversarial content within the processed video frames could potentially influence the model's output or the data subsequently stored in the agent's memory.
Audit Metadata