video-frame-reader

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The Python scripts extract_keyframes.py and scripts/extract_keyframes.py use the subprocess.run function to execute ffmpeg and ffprobe. These executions use argument lists rather than raw shell strings, which protects against command injection vulnerabilities from untrusted file paths.
  • [EXTERNAL_DOWNLOADS]: The skill instructions specify the installation of Pillow and numpy through the uv package manager. These are well-known and trusted Python libraries for image processing and mathematical operations.
  • [PROMPT_INJECTION]: The skill ingests external video data and passes frame information to a subagent for analysis. It implements boundary markers such as [User Intent] and [Frame Image Files] in the subagent prompt to distinguish between system instructions and untrusted content, mitigating the risk of indirect prompt injection.
  • [SAFE]: No obfuscation, data exfiltration, or persistence mechanisms were found. The skill behavior aligns correctly with its stated functionality of video frame analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 08:27 PM
Security Audit — agent-trust-hub — video-frame-reader