video-analyzer
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/analyze_video.pyutilizessubprocess.runto invoke external binaries includingyt-dlp,ffmpeg, andcurl. These calls are used for downloading video content, extracting frames/audio, and communicating with the OpenAI Whisper API. This execution is core to the skill's documented functionality. - [EXTERNAL_DOWNLOADS]: The skill downloads media files from third-party social media platforms (TikTok, YouTube, Instagram) via
yt-dlpbased on user-supplied URLs. The URLs are passed as single arguments to the subprocess call, which mitigates common shell injection risks. - [PROMPT_INJECTION]: The skill processes untrusted external data (video and audio content) which is analyzed by Vision and Speech-to-Text models. This constitutes an indirect prompt injection surface.
- Ingestion points: Media data downloaded from external URLs in
scripts/analyze_video.py. - Boundary markers: No specific delimiters or "ignore" instructions are present in the prompt templates used for the Gemini Vision API.
- Capability inventory: The skill can execute shell commands (
subprocess.run), write files, and make network requests viaurllib.requestandcurl. - Sanitization: Input URLs are handled via the subprocess list interface, providing protection against shell-level injection, though the content processed by the LLM is not sanitized for instructions.
- [SAFE_PRACTICE]: API keys for OpenAI and Gemini are retrieved from environment variables or a local
.envfile, adhering to standard security practices for managing sensitive credentials.
Audit Metadata