talking-head-production

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references installation instructions and documentation from the inference-sh GitHub repository and the inference.sh domain. These are used to guide the user in setting up the required CLI tools.
  • [COMMAND_EXECUTION]: Provides examples for executing the belt CLI tool to run AI models for video and image generation. These commands are the core purpose of the skill and are restricted by the allowed-tools configuration in the frontmatter.
  • [PROMPT_INJECTION]: The skill identifies an attack surface for indirect prompt injection by processing external image and audio URLs. However, this is a necessary part of the video production workflow and does not indicate malicious intent.
  • [SAFE]: No obfuscation, hardcoded credentials, or persistence mechanisms were found. The skill aligns with its stated purpose of teaching talking head video production.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 06:03 PM
Security Audit — agent-trust-hub — talking-head-production