videodb

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the videodb Python SDK and the python-dotenv package from the official Python Package Index (PyPI). These are standard dependencies for the VideoDB service.
  • [COMMAND_EXECUTION]: The skill operates by executing Python code through the Bash tool. This is the intended mechanism for interacting with the SDK to perform video processing tasks like indexing, searching, and timeline editing.
  • [CREDENTIALS_UNSAFE]: Secure secret management is emphasized; instructions direct users to store the VIDEO_DB_API_KEY in environment variables or a local .env file, rather than hardcoding credentials into scripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted data from video transcripts and AI-generated scene descriptions to be processed by an LLM.
  • Ingestion points: External data enters the context via video.get_transcript_text() and scene descriptions fetched from the VideoDB API.
  • Boundary markers: Most examples interpolate data directly into prompts without explicit delimiters (e.g., in reference/generative.md).
  • Capability inventory: The skill can perform network operations via the SDK, file system writes/reads, and execute system commands through the Bash tool.
  • Sanitization: There is no evidence of text sanitization or filtering on transcripts before they are passed to the LLM. However, this behavior is consistent with the primary purpose of video analysis skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:24 AM
Security Audit — agent-trust-hub — videodb