google-veo

Pass

Audited by Gen Agent Trust Hub on Apr 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill correctly limits its execution scope to the infsh CLI tool using the allowed-tools manifest field.
  • [EXTERNAL_DOWNLOADS]: The skill references installation scripts and documentation hosted on the vendor's official GitHub repository and domain (inference.sh), which are appropriate resources for the skill's functionality.
  • [COMMAND_EXECUTION]: All provided command examples are legitimate uses of the infsh tool for app discovery and execution, with no evidence of malicious intent or privilege escalation.
  • [PROMPT_INJECTION]: The skill processes user-generated prompts as data within structured JSON payloads for the video generation tool, incorporating natural boundaries between instructions and untrusted input.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 15, 2026, 01:59 PM
Security Audit — agent-trust-hub — google-veo