video-editing

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Credential Security: The skill follows best practices by instructing users to manage sensitive secrets like API keys through environment variables (e.g., ELEVENLABS_API_KEY).
  • [SAFE]: Network Operations: External network requests are directed towards well-known and reputable services, specifically ElevenLabs (api.elevenlabs.io) for text-to-speech generation.
  • [SAFE]: Command Execution: The provided FFmpeg commands and Remotion scripts are standard, deterministic tools used for video manipulation and programmatic composition, posing no risk in the context of the described workflow.
  • [SAFE]: Indirect Prompt Injection Surface: The skill naturally processes untrusted data in the form of video transcripts and source material. 1. Ingestion points: Source material transcripts are analyzed by Claude/Codex in Layer 2. 2. Boundary markers: No explicit delimiters or boundary warnings are provided in the example prompts. 3. Capability inventory: The skill utilizes subprocess execution for FFmpeg, network access via Python requests, and file-writing capabilities. 4. Sanitization: No explicit sanitization or validation of the input transcripts is shown. This surface is considered safe as it is essential to the core functionality of a video organization and editing tool.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 03:47 PM
Security Audit — agent-trust-hub — video-editing