video-audio

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/generate_audio.py uses the subprocess.run function to interact with ffmpeg for audio processing tasks, including determining audio duration, generating silent segments, and concatenating multiple audio files.
  • Evidence: Subprocess calls are used for FFmpeg operations with arguments passed as a list, which prevents shell injection. The binary path is configurable via the FFMPEG_PATH environment variable or defaults to a project-local bin directory.
  • [EXTERNAL_DOWNLOADS]: The skill connects to the ElevenLabs API (api.elevenlabs.io) to transform narration text into audio files. This is a well-known third-party service for Text-to-Speech.
  • [PROMPT_INJECTION]: The skill processes untrusted text data from a scenes.json file (specifically the narration field). While this text is passed to a TTS engine and not an LLM, it represents a surface for indirect prompt injection if the source data is attacker-controlled.
  • Ingestion points: scenes.json narration field.
  • Capability inventory: Local file writing (.mp3, .json), network communication via urllib.request, and local command execution via FFmpeg.
  • Sanitization: The skill performs no specific sanitization on the input text before sending it to the TTS API, which is standard for this utility's purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 08:27 PM
Security Audit — agent-trust-hub — video-audio