cli-anything-videocaptioner
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of external Python packages
cli-anything-videocaptionerandvideocaptionervia pip, as well as the installation of FFmpeg for video synthesis. The tool also includes adownloadcommand to fetch content from arbitrary URLs. - [COMMAND_EXECUTION]: The skill provides numerous commands for the agent to execute shell-level operations, including video transcription, subtitle processing, and file writing to the local system.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions designed to influence agent behavior.
- Ingestion points: The skill reads input from video files, subtitle files (SRT/ASS), script text files, and remote URLs (via the
downloadcommand). - Boundary markers: The instructions lack explicit boundary markers or directions for the agent to ignore potentially malicious embedded content within the processed files.
- Capability inventory: The skill has the capability to write files to disk (
-o PATH), access the network for transcription (Whisper API) and translation (Bing/Google), and download files from the internet. - Sanitization: No sanitization or validation logic is mentioned for the content extracted from processed videos or subtitle files.
Audit Metadata