google-veo

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructions and examples for interacting with the Google Veo service via its official 'belt' CLI tool. All referenced domains and repositories are legitimate service-related resources.
  • [EXTERNAL_DOWNLOADS]: Includes links to setup guides and documentation hosted on 'inference.sh' and its official GitHub repository ('inference-sh/skills'). These are documented neutrally as legitimate resources for the service provider.
  • [COMMAND_EXECUTION]: Example commands for video generation ('belt app run') are provided. The skill's execution environment is properly scoped and restricted to the 'belt' tool via the 'allowed-tools' metadata field.
  • [PROMPT_INJECTION]: The skill facilitates the processing of user-supplied prompts ('prompt' field in input JSON). While this presents an architectural surface for indirect prompt injection, it is the intended functionality of the video generation tool and does not indicate malicious intent.
  • Ingestion points: User-defined 'prompt' strings processed in SKILL.md examples.
  • Boundary markers: No explicit boundary markers or 'ignore' instructions are present in the documentation.
  • Capability inventory: Executes the 'belt' binary via the Bash tool to perform model inference.
  • Sanitization: No specific client-side sanitization is mentioned, as the skill relies on the external service's safety protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 07:31 AM
Security Audit — agent-trust-hub — google-veo