video-analyzer
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes system binaries
ffmpegandffprobeto perform media processing tasks. It also includes instructions for the agent to check for installed companion skills by listing contents of common hidden directories. - Evidence: SKILL.md contains numerous command recipes for
ffmpegandffprobe, and a "Companion check" block instructing the agent to runlson local skill directories. - [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose involves processing external video files and passing frames to AI vision models, which presents an inherent surface for indirect prompt injection from untrusted media content.
- Ingestion points: Video files (e.g., input.mp4) targeted for analysis.
- Boundary markers: Not explicitly defined in the provided FFmpeg workflows to isolate untrusted content from instructions.
- Capability inventory: Shell command execution (ffmpeg), file system access for writing frames, and AI vision tools for semantic analysis.
- Sanitization: No explicit validation or filtering of video content is implemented prior to processing.
Audit Metadata