fairstack-video-generation

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions for the FairStack video generation API are transparent and follow standard documentation practices. No hidden commands, obfuscation, or malicious instructions were detected.
  • [DATA_EXFILTRATION]: Network operations are restricted to communication with the vendor's official API endpoint (fairstack.ai). The skill promotes secure authentication by using environment variables for API keys rather than hardcoding credentials.
  • [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection through its ingestion of user prompts and external media URLs. 1. Ingestion points: prompt, image_url, last_image_url, and video_url parameters in SKILL.md. 2. Boundary markers: No specific delimiters or warnings are present in the examples. 3. Capability inventory: HTTP POST and GET requests to the external FairStack API. 4. Sanitization: Relies on the service provider's backend safety filters. This is a standard characteristic of media generation tools and does not represent a high-risk vulnerability in this context.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 09:05 PM
Security Audit — agent-trust-hub — fairstack-video-generation