magic-hour-image-to-video
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill uses official infrastructure belonging to the author (magichourhq). References to magichour.ai and github.com/magichourhq are standard for the intended video generation functionality.
- [SAFE]: The documentation in references/setup.md explicitly advises users to store the MAGIC_HOUR_API_KEY outside of source code, which is a recommended security practice for managing secrets.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user descriptions and images to generate video content. Instructions include manual verification steps (Inspect and deliver) that act as a security control, allowing the user to review the generated output for safety or accuracy before final delivery.
Audit Metadata