video-multimodal-generate

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes the meitu binary via the shell to perform video generation tasks.
  • [CREDENTIALS_UNSAFE]: The skill is configured to read authentication keys from ~/.meitu/credentials.json to facilitate API access for the meitu-cli tool.
  • [PROMPT_INJECTION]: The skill interpolates untrusted user data, including the text prompt and multiple URL lists, directly into a shell command string. This creates a potential indirect command injection surface where malicious input could attempt to execute arbitrary shell commands via subshell syntax or command separators.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 06:03 AM
Security Audit — agent-trust-hub — video-multimodal-generate