video-audio
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/generate_audio.pyuses thesubprocess.runfunction to interact withffmpegfor audio processing tasks, including determining audio duration, generating silent segments, and concatenating multiple audio files. - Evidence: Subprocess calls are used for FFmpeg operations with arguments passed as a list, which prevents shell injection. The binary path is configurable via the
FFMPEG_PATHenvironment variable or defaults to a project-local bin directory. - [EXTERNAL_DOWNLOADS]: The skill connects to the ElevenLabs API (
api.elevenlabs.io) to transform narration text into audio files. This is a well-known third-party service for Text-to-Speech. - [PROMPT_INJECTION]: The skill processes untrusted text data from a
scenes.jsonfile (specifically thenarrationfield). While this text is passed to a TTS engine and not an LLM, it represents a surface for indirect prompt injection if the source data is attacker-controlled. - Ingestion points:
scenes.jsonnarration field. - Capability inventory: Local file writing (
.mp3,.json), network communication viaurllib.request, and local command execution via FFmpeg. - Sanitization: The skill performs no specific sanitization on the input text before sending it to the TTS API, which is standard for this utility's purpose.
Audit Metadata