video-podcast-maker

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses Python's subprocess module to orchestrate media processing via ffmpeg, ffprobe, and the Remotion CLI. It constructs these commands as lists of arguments rather than shell strings, which is a secure pattern that prevents shell injection. These executions are essential for the skill's purpose of generating video and audio files.
  • [EXTERNAL_DOWNLOADS]: The skill fetches standard dependencies via npm and npx, and retrieves audio from cloud-based text-to-speech services (such as Azure or OpenAI). It also includes React components that can fetch Lottie animations or SRT subtitles from remote URLs. These network operations are standard for the intended workflow and target well-known, reputable providers.
  • [CREDENTIALS_UNSAFE]: The skill requires API keys for cloud services like Azure Speech and OpenAI. It handles these securely by encouraging the use of environment variables or .env files and includes a prerequisite check script (scripts/check_prereqs.py) to verify authentication before proceeding with synthesis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — video-podcast-maker