video-spec-builder
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes system-level commands including
ffmpeg,ffprobe, andplaywrightto process media assets, measure audio durations for timeline calculations, and perform visual validation of HTML layouts. - [EXTERNAL_DOWNLOADS]: Fetches article content from a conversion utility hosted on Hugging Face and retrieves images from WeChat servers and narration audio from the MiniMax cloud service.
- [PROMPT_INJECTION]: The skill ingests untrusted data from external WeChat articles as part of its automated conversion feature, representing an attack surface for indirect prompt injection. This is a known functional requirement and is mitigated by the skill's specific instruction to the agent to extract structured data rather than directly obey instructions within the article.
Audit Metadata