promo-video
Fail
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes
ffmpegandffprobefor audio normalization, mixing voiceovers with background tracks, and rendering video files. These are executed via shell commands and Python'ssubprocessmodule with argument lists. - [EXTERNAL_DOWNLOADS]: Fetches background music files from well-known services including Pixabay and Bensound. It also performs authenticated POST requests to the ElevenLabs API to download generated voiceover audio.
- [REMOTE_CODE_EXECUTION]: Bootstraps new video projects using
npx create-video@latest. This fetches and executes the latest project template from the npm registry at runtime. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it analyzes untrusted project data (README files, git logs, and source code) to automatically draft marketing scripts and voiceover text.
- Ingestion points: Reads
git log,README.md, and application model files inSKILL.md(Phase 1) to define the product context. - Boundary markers: No specific delimiters or instructions are provided to the agent to distinguish between its own logic and potentially malicious instructions embedded in the analyzed project data.
- Capability inventory: The skill has broad capabilities including file system access, network requests (ElevenLabs), and command execution (ffmpeg, npm).
- Sanitization: There is no evidence of sanitization or filtering applied to the text extracted from the project files before it is incorporated into the LLM's script-writing prompt.
Recommendations
- HIGH: Downloads and executes remote code from: unknown (check file) - DO NOT USE without thorough review
Audit Metadata