video-editor
Warn
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The script
scripts/compose_video.pyuploads local image frames tohttps://catbox.moe/user/api.phpusingcurl. While this is intended to provide public URLs for processing by the fal.ai API, it involves transmitting local project assets to an external third-party service. - [COMMAND_EXECUTION]: The skill uses
subprocess.runto executeffmpeg,fc-list, andcurl. While arguments are passed as lists, the script dynamically constructs complex ffmpeg filter strings (such aszoompananddrawtext) using data extracted fromscenes.jsonwithout rigorous validation. - [EXTERNAL_DOWNLOADS]: The skill interacts with the fal.ai API (
https://queue.fal.run/fal-ai/wan-i2v) to perform remote video generation tasks. Additionally, the script usesurllib.requestto poll for status updates from remote endpoints. - [REMOTE_CODE_EXECUTION]: The documentation in
SKILL.mdandSKILL.en.mdinstructs the user to runnpx remotion, which involves downloading and executing Node.js code from the npm registry at runtime. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes
scenes.jsonwithout sanitization. - Ingestion points:
scripts/compose_video.pyreadsscenes.jsonfor narration, text overlays, and composition parameters. - Boundary markers: No delimiters or safety instructions are present to prevent embedded commands in the JSON content from influencing the agent's behavior.
- Capability inventory: The script can execute shell commands (ffmpeg, curl) and perform network uploads and API requests.
- Sanitization: There is no evidence of filtering or sanitization of the input text used in video overlays or narration strings.
Audit Metadata