ai-video-generation

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to operate through the belt CLI tool using the Bash tool. This is the primary method for interacting with the vendor's video generation models.
  • [EXTERNAL_DOWNLOADS]: Fetches installation instructions and documentation from the vendor's official GitHub repository (inference-sh/skills) and website (inference.sh). These are documented as trusted vendor resources.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing external media content via URLs (images, video, audio) within JSON payloads passed to the generation models.
  • Ingestion points: Input fields such as image, video, audio, and reference_image in example belt commands.
  • Boundary markers: Uses structured JSON for model inputs, which helps separate data from commands.
  • Capability inventory: Utilizes the Bash tool to execute belt CLI commands for model inference and media processing.
  • Sanitization: The skill relies on the underlying belt CLI and the vendor's API to validate and sanitize provided URLs and parameters.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 08:13 AM
Security Audit — agent-trust-hub — ai-video-generation