video-podcast-maker
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses Python's
subprocessmodule to orchestrate media processing viaffmpeg,ffprobe, and the Remotion CLI. It constructs these commands as lists of arguments rather than shell strings, which is a secure pattern that prevents shell injection. These executions are essential for the skill's purpose of generating video and audio files. - [EXTERNAL_DOWNLOADS]: The skill fetches standard dependencies via
npmandnpx, and retrieves audio from cloud-based text-to-speech services (such as Azure or OpenAI). It also includes React components that can fetch Lottie animations or SRT subtitles from remote URLs. These network operations are standard for the intended workflow and target well-known, reputable providers. - [CREDENTIALS_UNSAFE]: The skill requires API keys for cloud services like Azure Speech and OpenAI. It handles these securely by encouraging the use of environment variables or
.envfiles and includes a prerequisite check script (scripts/check_prereqs.py) to verify authentication before proceeding with synthesis.
Audit Metadata