promo-video

Fail

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes ffmpeg and ffprobe for audio normalization, mixing voiceovers with background tracks, and rendering video files. These are executed via shell commands and Python's subprocess module with argument lists.
  • [EXTERNAL_DOWNLOADS]: Fetches background music files from well-known services including Pixabay and Bensound. It also performs authenticated POST requests to the ElevenLabs API to download generated voiceover audio.
  • [REMOTE_CODE_EXECUTION]: Bootstraps new video projects using npx create-video@latest. This fetches and executes the latest project template from the npm registry at runtime.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it analyzes untrusted project data (README files, git logs, and source code) to automatically draft marketing scripts and voiceover text.
  • Ingestion points: Reads git log, README.md, and application model files in SKILL.md (Phase 1) to define the product context.
  • Boundary markers: No specific delimiters or instructions are provided to the agent to distinguish between its own logic and potentially malicious instructions embedded in the analyzed project data.
  • Capability inventory: The skill has broad capabilities including file system access, network requests (ElevenLabs), and command execution (ffmpeg, npm).
  • Sanitization: There is no evidence of sanitization or filtering applied to the text extracted from the project files before it is incorporated into the LLM's script-writing prompt.
Recommendations
  • HIGH: Downloads and executes remote code from: unknown (check file) - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — promo-video