skills/mblode/video-studio/vs/Gen Agent Trust Hub

vs

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill operates by executing local system commands to process and assemble media files. This includes invoking ffmpeg and ffprobe for video assembly, audio mixing, and stream probing (as detailed in references/assembly.md and references/audio-mix.md). On macOS environments, the skill also shells out to qlmanage and sips to rasterize title cards.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources including shots.json, stills.json, and lines.tsv to drive its automated generation and assembly workflows.
  • Ingestion points: Structured film configuration files (shots.json, stills.json) and narration TSV files (lines.tsv) ingested by commands like vs generate and vs narrate.
  • Boundary markers: The provided documentation does not specify the use of delimiters or warnings to prevent the agent from following instructions embedded within these data files.
  • Capability inventory: Execution of local binaries (ffmpeg, qlmanage, sips) and network interaction with AI provider endpoints (BytePlus, Vercel, Google, ElevenLabs).
  • Sanitization: The documentation does not describe sanitization or escaping routines for data interpolated into shell command strings or API request bodies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:00 PM
Security Audit — agent-trust-hub — vs