magic-hour-image-to-video

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill uses official infrastructure belonging to the author (magichourhq). References to magichour.ai and github.com/magichourhq are standard for the intended video generation functionality.
  • [SAFE]: The documentation in references/setup.md explicitly advises users to store the MAGIC_HOUR_API_KEY outside of source code, which is a recommended security practice for managing secrets.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user descriptions and images to generate video content. Instructions include manual verification steps (Inspect and deliver) that act as a security control, allowing the user to review the generated output for safety or accuracy before final delivery.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 05:10 PM
Security Audit — agent-trust-hub — magic-hour-image-to-video