mv-composer

Warn

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructions include a command to read sensitive environment variables from a file in the parent directory (../.env) using grep '^FAL_KEY='. Accessing credentials outside the skill's specific directory is a high-risk pattern for data exposure.
  • [EXTERNAL_DOWNLOADS]: The skill uses a dedicated shell script scripts/download_assets.sh to fetch remote resources, which can introduce unverified content into the local environment.
  • [COMMAND_EXECUTION]: The workflow relies on executing multiple local scripts for core functionality, including scripts/i2v_batch.py, scripts/generate_viral_script.py, and scripts/video_qa.py. While functional, this requires broad execution permissions.
  • [PROMPT_INJECTION]: The Video QA pipeline (scripts/video_qa.py) introduces an indirect prompt injection surface. It ingests untrusted visual and audio data (video frames and narration) and processes them using Gemini Vision for "Director Review" and scoring. A lack of explicit boundary markers or sanitization could allow malicious content within the generated video to influence the AI's final quality assessment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — mv-composer