ai-avatar-video

Pass

Audited by Gen Agent Trust Hub on Apr 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate integration for the inference.sh platform, providing users with commands to generate AI media using official tools.
  • [COMMAND_EXECUTION]: The skill provides examples for executing the infsh command. The execution environment is restricted to the infsh tool as defined in the allowed-tools section of the YAML frontmatter.
  • [EXTERNAL_DOWNLOADS]: References installation scripts and related skills located on the official GitHub repository for the vendor (inference-sh/skills). These are verified vendor resources and do not pose a third-party supply chain risk.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it processes external data from URLs (images, audio, video).
  • Ingestion points: image_url, audio_url, and video_url parameters in the infsh app run commands (SKILL.md).
  • Boundary markers: Absent; the skill relies on the underlying models and CLI for input handling.
  • Capability inventory: Commands are limited to the infsh CLI tool via Bash (SKILL.md).
  • Sanitization: No explicit sanitization or validation of external URLs is performed within the instructions.
  • Note: This is a low-level risk inherent to any tool that processes untrusted external media.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 15, 2026, 01:58 PM
Security Audit — agent-trust-hub — ai-avatar-video