ai-video-generation
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
subprocessmodule to run external binaries such asffmpegandrealesrgan-ncnn-vulkan. These tools are used for legitimate video processing tasks including frame interpolation, upscaling, artifact removal, and concatenating video files. - [EXTERNAL_DOWNLOADS]: The
StoryboardRendererclass and various API clients use therequestslibrary to fetch video content from external URLs provided by AI video platforms (e.g., Runway, Pika). These downloads are necessary for the skill's primary function of generating and retrieving video assets. - [INDIRECT_PROMPT_INJECTION]: The skill acts as an integration layer for AI models, processing user-provided text and image prompts. While this presents a surface for indirect prompt injection, it is the core functionality of the skill.
- Ingestion points: Prompts are ingested via the
GenerationRequestclass inSKILL.mdand passed to external APIs. - Boundary markers: The code does not implement specific boundary markers or sanitization for prompt strings, relying on the safety filters of the target AI platforms.
- Capability inventory: The skill has the ability to perform network requests (
requests), execute shell commands viasubprocess, and write files to the local disk. - Sanitization: No explicit sanitization of input prompts is performed before they are sent to the generation APIs.
Audit Metadata