ai-video-gen

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected.- [DATA_EXFILTRATION]: All network operations are directed to the vendor's official domain api.heygen.com for video generation and status checking. This is consistent with the skill's stated purpose.- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied prompts and optional external image URLs as inputs for video generation workflows. While these are entry points for external data, the risk is inherent to the service's functionality.
  • Ingestion points: input.prompt and input.reference_image_url in SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: Network requests (POST/GET) to api.heygen.com using the mcp__heygen__* tools.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 10:07 AM
Security Audit — agent-trust-hub — ai-video-gen