video-ingest

Fail

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The health check section describes a command that pipes network output into the Python interpreter: curl -s http://localhost:3111/ | python3 -c "...". Although this specific instance uses an inline script (-c) to parse data from a local service rather than executing the downloaded content, the pattern of piping network data to a language interpreter is a high-risk capability that could be misused if the endpoint is compromised or the command is modified.
  • [COMMAND_EXECUTION]: The skill utilizes several powerful system-level tools to manage the video pipeline, including kubectl for restarting deployments, docker for monitoring event dispatch, and a custom CLI tool joelclaw. These commands allow the agent to interact directly with the host's infrastructure and container orchestration.
  • [DYNAMIC_EXECUTION]: The skill provides an inline Python script within the health check section to parse JSON data. This allows for the dynamic processing of system state information using the local Python environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external, untrusted content from video platforms and meeting transcripts, creating a vulnerability surface for indirect prompt injection.
  • Ingestion points: The skill accepts external data via the url field in pipeline/video.requested and the text field in pipeline/transcript.requested.
  • Boundary markers: There are no explicit instructions or delimiters provided to the agent to treat ingested transcript data as untrusted or to ignore instructions embedded within that data.
  • Capability inventory: The skill possesses broad capabilities, including writing to local and network storage (Vault and NAS), managing Kubernetes pods, and executing Docker commands.
  • Sanitization: No sanitization or validation logic is described to filter malicious instructions out of the video transcripts or meeting notes before they are processed by the agent.
Recommendations
  • HIGH: Downloads and executes remote code from: http://localhost:3111/ - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — video-ingest