video
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill generates Node.js scripts (e.g., corelive/record.mjs) and executes them using the local environment to drive browser automation. It also makes extensive use of shell commands such as ffmpeg, ffprobe, and screencapture to manipulate and record media files.
- [PROMPT_INJECTION]: The skill extracts frames from user-provided or captured video files for visual inspection (Ingestion points: SKILL.md, references/ffmpeg-recipes.md). While the agent possesses broad capabilities including subprocess execution and file manipulation, the analysis workflow lacks specific boundary markers or sanitization logic to mitigate instructions that may be embedded within the processed video content (Indirect Prompt Injection surface).
- [EXTERNAL_DOWNLOADS]: The skill relies on well-known and trusted external resources, including the Playwright framework and the ffmpeg utility, for its core media processing and automation tasks.
Audit Metadata