video-ingest
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The health check section describes a command that pipes network output into the Python interpreter:
curl -s http://localhost:3111/ | python3 -c "...". Although this specific instance uses an inline script (-c) to parse data from a local service rather than executing the downloaded content, the pattern of piping network data to a language interpreter is a high-risk capability that could be misused if the endpoint is compromised or the command is modified. - [COMMAND_EXECUTION]: The skill utilizes several powerful system-level tools to manage the video pipeline, including
kubectlfor restarting deployments,dockerfor monitoring event dispatch, and a custom CLI tooljoelclaw. These commands allow the agent to interact directly with the host's infrastructure and container orchestration. - [DYNAMIC_EXECUTION]: The skill provides an inline Python script within the health check section to parse JSON data. This allows for the dynamic processing of system state information using the local Python environment.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external, untrusted content from video platforms and meeting transcripts, creating a vulnerability surface for indirect prompt injection.
- Ingestion points: The skill accepts external data via the
urlfield inpipeline/video.requestedand thetextfield inpipeline/transcript.requested. - Boundary markers: There are no explicit instructions or delimiters provided to the agent to treat ingested transcript data as untrusted or to ignore instructions embedded within that data.
- Capability inventory: The skill possesses broad capabilities, including writing to local and network storage (
VaultandNAS), managing Kubernetes pods, and executing Docker commands. - Sanitization: No sanitization or validation logic is described to filter malicious instructions out of the video transcripts or meeting notes before they are processed by the agent.
Recommendations
- HIGH: Downloads and executes remote code from: http://localhost:3111/ - DO NOT USE without thorough review
Audit Metadata