mike-cartoon-broll

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses a Node.js helper script to manage interactions with the OpenRouter Video API, a well-known service provider.- [CREDENTIALS_UNSAFE]: The script scripts/openrouter-video.mjs accesses the OPENROUTER_API_KEY from environment variables or .env files. It checks specific paths such as ~/dev/me/agent-skills/.env to locate these credentials. This is standard secret management for developer tools and the key is used only for legitimate API calls.- [EXTERNAL_DOWNLOADS]: The skill downloads generated video content from OpenRouter's infrastructure. These downloads are requested by the user and handled by the included script.- [COMMAND_EXECUTION]: The helper script performs filesystem operations such as creating directories and writing files within the project's source/generated folder. These actions are restricted to the local workspace.- [PROMPT_INJECTION]: The skill processes user-supplied script segments to generate video prompts. Ingestion points: User script lines processed in the ideation workflow. Boundary markers: Instructions mandate extracting semantic anchors and literal baselines. Capability inventory: The agent writes to the local filesystem and interacts with the OpenRouter API. Sanitization: The agent performs internal frame checks and motion brief reconciliation against anchors.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 09:45 PM
Security Audit — agent-trust-hub — mike-cartoon-broll