videodb
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
videodbPython SDK and thepython-dotenvpackage from the official Python Package Index (PyPI). These are standard dependencies for the VideoDB service. - [COMMAND_EXECUTION]: The skill operates by executing Python code through the
Bashtool. This is the intended mechanism for interacting with the SDK to perform video processing tasks like indexing, searching, and timeline editing. - [CREDENTIALS_UNSAFE]: Secure secret management is emphasized; instructions direct users to store the
VIDEO_DB_API_KEYin environment variables or a local.envfile, rather than hardcoding credentials into scripts. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted data from video transcripts and AI-generated scene descriptions to be processed by an LLM.
- Ingestion points: External data enters the context via
video.get_transcript_text()and scene descriptions fetched from the VideoDB API. - Boundary markers: Most examples interpolate data directly into prompts without explicit delimiters (e.g., in
reference/generative.md). - Capability inventory: The skill can perform network operations via the SDK, file system writes/reads, and execute system commands through the
Bashtool. - Sanitization: There is no evidence of text sanitization or filtering on transcripts before they are passed to the LLM. However, this behavior is consistent with the primary purpose of video analysis skills.
Audit Metadata