video

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation includes instructions to install well-known libraries such as hyperframes and remotion using standard package managers. These resources are from established providers in the video automation space.- [COMMAND_EXECUTION]: The programmatic video workflows involve executing scripts (Node.js/React) to render video content from templates. This is a primary and necessary function of the skill.- [PROMPT_INJECTION]: The skill implements a context-gathering step by reading local marketing files (e.g., .agents/product-marketing.md). While this provides a surface for indirect prompt injection, it is used here to improve the relevance of generated video scripts and is common practice for specialized AI agents.
  • Ingestion points: Reads .agents/product-marketing.md and similar local files in SKILL.md.
  • Boundary markers: None identified.
  • Capability inventory: The skill uses code execution for video rendering and integrated tool calls via the HeyGen MCP server.
  • Sanitization: Standard input processing is implied for the intended use cases.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 05:31 AM
Security Audit — agent-trust-hub — video