gif-sticker-maker

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the ffmpeg system utility for converting generated videos into animated GIFs. The execution is handled via the subprocess module in scripts/convert_mp4_to_gif.py using a list-based argument structure, which prevents common command injection vulnerabilities.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: Authentication for the MiniMax APIs is managed via environment variables (MINIMAX_API_KEY), which avoids the risk of hardcoded secrets. Data transmission is limited to sending user-supplied content to legitimate API endpoints for generation.\n- [INDIRECT_PROMPT_INJECTION]: The skill interpolates user-provided photos and caption text into prompt templates for media generation. This represents a standard attack surface for creative tools, but it is not exploitable beyond influencing the content of the generated GIF.\n
  • Ingestion points: User-supplied images and localized caption text are ingested by scripts/minimax_image.py and scripts/minimax_video.py.\n
  • Boundary markers: Prompt templates provide structural grouping for subject handling and actions, though they lack explicit safety delimiters.\n
  • Capability inventory: The skill possesses capabilities for network requests (API calls) and local file conversion (ffmpeg).\n
  • Sanitization: No specialized filtering or sanitization of user-provided captions is performed before interpolation into the generation prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — gif-sticker-maker