video-spec-builder

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes system-level commands including ffmpeg, ffprobe, and playwright to process media assets, measure audio durations for timeline calculations, and perform visual validation of HTML layouts.
  • [EXTERNAL_DOWNLOADS]: Fetches article content from a conversion utility hosted on Hugging Face and retrieves images from WeChat servers and narration audio from the MiniMax cloud service.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from external WeChat articles as part of its automated conversion feature, representing an attack surface for indirect prompt injection. This is a known functional requirement and is mitigated by the skill's specific instruction to the agent to extract structured data rather than directly obey instructions within the article.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 04:51 AM
Security Audit — agent-trust-hub — video-spec-builder