video-editing
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted video transcripts to generate FFmpeg commands and structure edits, creating a surface for indirect prompt injection.
- Ingestion points: Video transcripts processed in Layer 2.
- Boundary markers: None provided in the instruction templates to isolate transcript content.
- Capability inventory: Execution of FFmpeg shell commands, bash script generation, and ElevenLabs API requests.
- Sanitization: No content validation or sanitization is performed on transcripts before they influence command output.
- [COMMAND_EXECUTION]: Generates and executes FFmpeg commands and bash scripts for video processing, as well as npx commands for Remotion rendering.
- [EXTERNAL_DOWNLOADS]: Fetches generated voice and media assets from ElevenLabs and fal.ai official APIs, which are well-known services.
Audit Metadata