google-veo
Pass
Audited by Gen Agent Trust Hub on Apr 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill correctly limits its execution scope to the
infshCLI tool using theallowed-toolsmanifest field. - [EXTERNAL_DOWNLOADS]: The skill references installation scripts and documentation hosted on the vendor's official GitHub repository and domain (
inference.sh), which are appropriate resources for the skill's functionality. - [COMMAND_EXECUTION]: All provided command examples are legitimate uses of the
infshtool for app discovery and execution, with no evidence of malicious intent or privilege escalation. - [PROMPT_INJECTION]: The skill processes user-generated prompts as data within structured JSON payloads for the video generation tool, incorporating natural boundaries between instructions and untrusted input.
Audit Metadata