changelog-video

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute multiple shell commands for its operations. This includes using ffmpeg for video encoding and processing, node to run included scripts for TTS alignment and project validation, and uvx for running the openai-whisper model. It also uses the aws CLI for CloudFront cache invalidation and the heygen CLI for voice synthesis.
  • [EXTERNAL_DOWNLOADS]: The skill relies on external libraries and tools. The video composition template (master-skeleton.html) loads the GSAP animation library from a public CDN (JSDelivr). Additionally, the skill utilizes uvx to dynamically run the openai-whisper package for audio alignment if primary timestamping fails.
  • [INDIRECT_PROMPT_INJECTION]: The skill functions by ingesting untrusted markdown data (user changelogs) to drive the narrative and visualization logic of the video. While this processes external content, the risk is mitigated by the highly structured build process that maps items to a predefined visualization registry and uses a rigid HTML/CSS/JS scaffold.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 10:55 PM
Security Audit — agent-trust-hub — changelog-video