video-editor

Warn

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The script scripts/compose_video.py uploads local image frames to https://catbox.moe/user/api.php using curl. While this is intended to provide public URLs for processing by the fal.ai API, it involves transmitting local project assets to an external third-party service.
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to execute ffmpeg, fc-list, and curl. While arguments are passed as lists, the script dynamically constructs complex ffmpeg filter strings (such as zoompan and drawtext) using data extracted from scenes.json without rigorous validation.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with the fal.ai API (https://queue.fal.run/fal-ai/wan-i2v) to perform remote video generation tasks. Additionally, the script uses urllib.request to poll for status updates from remote endpoints.
  • [REMOTE_CODE_EXECUTION]: The documentation in SKILL.md and SKILL.en.md instructs the user to run npx remotion, which involves downloading and executing Node.js code from the npm registry at runtime.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes scenes.json without sanitization.
  • Ingestion points: scripts/compose_video.py reads scenes.json for narration, text overlays, and composition parameters.
  • Boundary markers: No delimiters or safety instructions are present to prevent embedded commands in the JSON content from influencing the agent's behavior.
  • Capability inventory: The script can execute shell commands (ffmpeg, curl) and perform network uploads and API requests.
  • Sanitization: There is no evidence of filtering or sanitization of the input text used in video overlays or narration strings.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 20, 2026, 01:04 PM
Security Audit — agent-trust-hub — video-editor