embed-media-engine-desktop

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a technical architectural guide for developers. It outlines best practices for handling native handles, thread ownership, and initialization sequences for media engines like MPV.
  • [COMMAND_EXECUTION]: The skill includes grep commands intended for local source code auditing within a specific project directory structure (core/media/media-jvm/...). These commands are static, do not incorporate unsanitized user input, and are restricted to searching local files for verification purposes. There is no evidence of command injection or dangerous shell operations.
  • [PROMPT_INJECTION]: The content is purely instructional and technical. It does not contain instructions that attempt to override AI behavior, bypass safety guardrails, or extract system prompts.
  • [DATA_EXPOSURE]: The skill does not access sensitive file paths (e.g., SSH keys, cloud credentials), nor does it contain hardcoded secrets. It operates exclusively on project source code.
  • [EXTERNAL_DOWNLOADS]: No remote dependencies or external scripts are downloaded or executed. The verification steps rely on local filesystem checks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 07:02 AM
Security Audit — agent-trust-hub — embed-media-engine-desktop