ffmpeg
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes FFmpeg commands by passing user-supplied arguments directly to a containerized binary, which is the intended functional purpose of the tool.
- [EXTERNAL_DOWNLOADS]: The skill references the 'linuxserver/ffmpeg:latest' image from Docker Hub, which is an official repository from a well-known and reputable community organization.
- [SAFE]: The configuration explicitly disables network access ('network = none'), which mitigates risks of data exfiltration and prevents FFmpeg from making unexpected remote connections.
- [SAFE]: Filesystem access is strictly limited to the user's current working directory through controlled volume mounting, protecting the host system's sensitive directories.
- [SAFE]: The skill defines clear resource boundaries (2GB memory, 4 CPU cores) to prevent denial-of-service conditions on the host during intensive media transcoding operations.
Audit Metadata