google-veo
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied prompts which are passed to the
beltCLI for video generation. - Ingestion points: The
promptfield in JSON payloads forbelt app runcommands inSKILL.md. - Boundary markers: Absent.
- Capability inventory: Execution of
beltCLI commands via theBashtool. - Sanitization: No input sanitization or validation logic is defined in the skill instructions.
- [EXTERNAL_DOWNLOADS]: The skill fetches configuration and adds skills from the
inference-shecosystem and its associated GitHub repository.
Audit Metadata