skills/joydai2026-del/skills/vid-qa/Gen Agent Trust Hub

vid-qa

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides detailed instructions for performing quality assurance on video files using established command-line utilities. The instructions focus on technical validation (frame sampling, audio integrity, file container checks) and human review protocols.
  • [COMMAND_EXECUTION]: The skill specifies the use of ffmpeg and ffprobe for diagnostic tasks, such as verifying file duration, detecting audio clipping (volumedetect), and checking container metadata (movflags, color_range). These are standard uses of local utilities for media analysis and do not involve executing untrusted code or external payloads.
  • [DATA_EXPOSURE]: The skill does not contain hardcoded credentials, API keys, or sensitive system paths. It refers to local project assets (reference frames, criteria files) and utilizes ffprobe for metadata extraction, which is consistent with its stated purpose of video QA.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external inputs in the form of AI-generated videos and configuration files (video-criteria.yaml). It mitigates risks by implementing a 'Layer 0' deterministic floor that validates file integrity (size, duration, corrupt container checks) before performing higher-level visual or auditory analysis.
  • [OBFUSCATION]: A thorough review of the technical instructions and the Chinese-language post-mortem addenda reveals no hidden instructions, homoglyph attacks, or encoded payloads. The Chinese text provides technical details regarding mobile UI safe zones, audio normalization standards, and video encoding profiles.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:07 AM
Security Audit — agent-trust-hub — vid-qa