skills/iwanhe/pandawa/demo-video/Gen Agent Trust Hub

demo-video

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill generates a build.sh shell script to orchestrate video production tasks using local tools like FFmpeg and Playwright. This is a core component of its documented workflow for video rendering.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied scene descriptions and screenshots to generate HTML files and narration text.\n
  • Ingestion points: User-provided scene descriptions and screenshots from the prompt.\n
  • Boundary markers: None explicitly defined in the instructions for generating HTML scenes.\n
  • Capability inventory: File system writes (creating the demo-output/ directory) and shell script generation.\n
  • Sanitization: No explicit sanitization of user input is specified for the generated HTML or narration content.\n- [DYNAMIC_EXECUTION]: The skill dynamically generates shell scripts and HTML content based on user input. This behavior is consistent with its primary purpose of creating custom video assets and does not incorporate untrusted external input into security-sensitive execution contexts.\n- [EXTERNAL_DOWNLOADS]: The skill references an external repository at github.com/vaddisrinivas/framecraft as a related tool. This is a reference to a well-known service and the documentation is neutral.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:32 PM
Security Audit — agent-trust-hub — demo-video