video-reverse-engineer

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the subprocess module in analyze.py to execute ffmpeg for extracting audio and performing media transcoding. This is a primary function of the skill but involves direct interaction with the system shell.
  • [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface where data extracted from external video files could potentially influence agent behavior.
  • Ingestion points: Audio from video files is transcribed into text via mlx-whisper and included in the final analysis report.
  • Boundary markers: Transcribed content is formatted within Markdown blockquotes in the output report, but the skill lacks explicit instructions to the agent to ignore any commands found within the transcribed text.
  • Capability inventory: The agent has access to file system operations and shell command execution through the skill's primary script and environment.
  • Sanitization: There is no evidence of filtering or sanitization performed on the transcribed text to prevent embedded instructions from being processed by the LLM.
  • [EXTERNAL_DOWNLOADS]: The mlx-whisper library used in analyze.py downloads pre-trained model weights from Hugging Face repositories. While Hugging Face is a well-known service, this involves fetching external assets at runtime.
  • [DATA_EXFILTRATION]: Documentation in SKILL.md contains hardcoded absolute file paths (e.g., /Users/baimengke/Documents/...) that expose local directory structures and the author's username.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 03:47 PM
Security Audit — agent-trust-hub — video-reverse-engineer