lov-media-creator

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Several scripts, including audio_qc.py, media_probe.py, subtitle_gate.py, and check_opening_still.py, execute the ffmpeg and ffprobe binaries using subprocess.run(). The implementation passes arguments as lists and does not utilize shell=True, which effectively prevents common command injection vulnerabilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data during the video processing workflow.
  • Ingestion points: Media metadata and transcript files provided by the user or extracted from .screenstudio bundles are ingested in scripts/media_probe.py and scripts/subtitle_gate.py.
  • Boundary markers: The instructions describe complex validation workflows, but there are no explicit prompt delimiters (like XML tags) used when the agent processes ASR (Automatic Speech Recognition) text or transcript content.
  • Capability inventory: The skill has the capability to execute shell commands via FFmpeg wrappers and perform extensive file writes in the project workspace (documented in scripts/subtitle_gate.py and SKILL.md).
  • Sanitization: The skill implements "Quality Gates," such as semantic ASR verification and structural validation of SubRip (SRT) files, which mitigates the risk of the agent accidentally interpreting data as instructions.
  • [PROMPT_INJECTION]: A deterministic detector flagged a potential concealment pattern in skill-card.md. Manual analysis confirms the text refers to preventing the agent from fabricating success claims (a transparency requirement) rather than an attempt to hide the agent's actions from the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 09:05 AM
Security Audit — agent-trust-hub — lov-media-creator