heygen
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of documentation (Markdown files) and code snippets for integrating with the HeyGen API. No executable scripts or binary files are included.
- [SAFE]: Authentication is handled via the HEYGEN_API_KEY environment variable. The provided examples follow security best practices by using environment-based secret management (e.g., process.env.HEYGEN_API_KEY) rather than hardcoding credentials.
- [EXTERNAL_DOWNLOADS]: The documentation describes workflows for fetching generated video content and assets from the vendor's official delivery domains (e.g., files.heygen.ai, resource2.heygen.ai). These are legitimate service endpoints associated with the skill's primary purpose.
- [DATA_EXFILTRATION]: The skill documentation outlines procedures for uploading user-provided media assets (images, audio, video) to the vendor's official upload endpoint (upload.heygen.com). This functionality is inherent to the service and directed to the vendor's own infrastructure.
Audit Metadata