cli-anything-videocaptioner

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of external Python packages cli-anything-videocaptioner and videocaptioner via pip, as well as the installation of FFmpeg for video synthesis. The tool also includes a download command to fetch content from arbitrary URLs.
  • [COMMAND_EXECUTION]: The skill provides numerous commands for the agent to execute shell-level operations, including video transcription, subtitle processing, and file writing to the local system.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions designed to influence agent behavior.
  • Ingestion points: The skill reads input from video files, subtitle files (SRT/ASS), script text files, and remote URLs (via the download command).
  • Boundary markers: The instructions lack explicit boundary markers or directions for the agent to ignore potentially malicious embedded content within the processed files.
  • Capability inventory: The skill has the capability to write files to disk (-o PATH), access the network for transcription (Whisper API) and translation (Bing/Google), and download files from the internet.
  • Sanitization: No sanitization or validation logic is mentioned for the content extracted from processed videos or subtitle files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:16 AM
Security Audit — agent-trust-hub — cli-anything-videocaptioner