video-analysis

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data (video files, URLs, and screenshots) to extract parameters that are subsequently used to optimize "prompt-matrix" and "industry skills" templates. This creates an indirect prompt injection surface.
  • Ingestion points: Processes external video sources and URLs as defined in the 'Video Input' step of SKILL.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded content were found in the processing workflow.
  • Capability inventory: Performs file writing operations to the ~/.claude/case-library/ directory to store analysis results.
  • Sanitization: No explicit validation or sanitization of extracted video metadata is mentioned before it is archived or used for template updates.
  • [DATA_EXPOSURE]: The skill manages a local database of analyzed content within the hidden directory ~/.claude/case-library/. This is a persistent storage mechanism for metadata extracted by the agent.
  • [COMMAND_EXECUTION]: The documentation includes example bash commands (using grep) intended for the user to manually search through the archived JSON files; these commands are not automated by the skill logic.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 03:47 PM
Security Audit — agent-trust-hub — video-analysis