lov-media-creator
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Several scripts, including
audio_qc.py,media_probe.py,subtitle_gate.py, andcheck_opening_still.py, execute theffmpegandffprobebinaries usingsubprocess.run(). The implementation passes arguments as lists and does not utilizeshell=True, which effectively prevents common command injection vulnerabilities. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data during the video processing workflow.
- Ingestion points: Media metadata and transcript files provided by the user or extracted from
.screenstudiobundles are ingested inscripts/media_probe.pyandscripts/subtitle_gate.py. - Boundary markers: The instructions describe complex validation workflows, but there are no explicit prompt delimiters (like XML tags) used when the agent processes ASR (Automatic Speech Recognition) text or transcript content.
- Capability inventory: The skill has the capability to execute shell commands via FFmpeg wrappers and perform extensive file writes in the project workspace (documented in
scripts/subtitle_gate.pyandSKILL.md). - Sanitization: The skill implements "Quality Gates," such as semantic ASR verification and structural validation of SubRip (SRT) files, which mitigates the risk of the agent accidentally interpreting data as instructions.
- [PROMPT_INJECTION]: A deterministic detector flagged a potential concealment pattern in
skill-card.md. Manual analysis confirms the text refers to preventing the agent from fabricating success claims (a transparency requirement) rather than an attempt to hide the agent's actions from the user.
Audit Metadata