mv-composer
Warn
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill instructions include a command to read sensitive environment variables from a file in the parent directory (
../.env) usinggrep '^FAL_KEY='. Accessing credentials outside the skill's specific directory is a high-risk pattern for data exposure. - [EXTERNAL_DOWNLOADS]: The skill uses a dedicated shell script
scripts/download_assets.shto fetch remote resources, which can introduce unverified content into the local environment. - [COMMAND_EXECUTION]: The workflow relies on executing multiple local scripts for core functionality, including
scripts/i2v_batch.py,scripts/generate_viral_script.py, andscripts/video_qa.py. While functional, this requires broad execution permissions. - [PROMPT_INJECTION]: The Video QA pipeline (
scripts/video_qa.py) introduces an indirect prompt injection surface. It ingests untrusted visual and audio data (video frames and narration) and processes them using Gemini Vision for "Director Review" and scoring. A lack of explicit boundary markers or sanitization could allow malicious content within the generated video to influence the AI's final quality assessment.
Audit Metadata