gif-sticker-maker
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
ffmpegsystem utility for converting generated videos into animated GIFs. The execution is handled via thesubprocessmodule inscripts/convert_mp4_to_gif.pyusing a list-based argument structure, which prevents common command injection vulnerabilities.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: Authentication for the MiniMax APIs is managed via environment variables (MINIMAX_API_KEY), which avoids the risk of hardcoded secrets. Data transmission is limited to sending user-supplied content to legitimate API endpoints for generation.\n- [INDIRECT_PROMPT_INJECTION]: The skill interpolates user-provided photos and caption text into prompt templates for media generation. This represents a standard attack surface for creative tools, but it is not exploitable beyond influencing the content of the generated GIF.\n - Ingestion points: User-supplied images and localized caption text are ingested by
scripts/minimax_image.pyandscripts/minimax_video.py.\n - Boundary markers: Prompt templates provide structural grouping for subject handling and actions, though they lack explicit safety delimiters.\n
- Capability inventory: The skill possesses capabilities for network requests (API calls) and local file conversion (ffmpeg).\n
- Sanitization: No specialized filtering or sanitization of user-provided captions is performed before interpolation into the generation prompts.
Audit Metadata