video-analyzer

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes system binaries ffmpeg and ffprobe to perform media processing tasks. It also includes instructions for the agent to check for installed companion skills by listing contents of common hidden directories.
  • Evidence: SKILL.md contains numerous command recipes for ffmpeg and ffprobe, and a "Companion check" block instructing the agent to run ls on local skill directories.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose involves processing external video files and passing frames to AI vision models, which presents an inherent surface for indirect prompt injection from untrusted media content.
  • Ingestion points: Video files (e.g., input.mp4) targeted for analysis.
  • Boundary markers: Not explicitly defined in the provided FFmpeg workflows to isolate untrusted content from instructions.
  • Capability inventory: Shell command execution (ffmpeg), file system access for writing frames, and AI vision tools for semantic analysis.
  • Sanitization: No explicit validation or filtering of video content is implemented prior to processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:22 PM
Security Audit — agent-trust-hub — video-analyzer