bangumi-frames
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes ffmpeg for frame extraction and yt-dlp for downloading Bilibili content via subprocess.run. Analysis confirms these calls use list-based arguments with shell=False, protecting against command injection attacks.
- [EXTERNAL_DOWNLOADS]: The skill fetches anime person detection and CCIP models from HuggingFace and inpainting weights from GitHub. These are standard resources for AI-based image processing.
- [SAFE]: Authentication is managed through local Netscape-format cookie files. The skill provides a default path and environment variable support, following standard practices for local credential handling.
Audit Metadata