video-playbook

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a management tool for processing video analysis results locally. Analysis of the manage_playbook.py script confirms it only performs local JSON and Markdown file operations within the skill's directory. It does not initiate network connections, access sensitive system credentials, or execute arbitrary shell commands.
  • [PROMPT_INJECTION]: The skill processes untrusted text data, such as video transcripts and summaries, from template.json files and incorporates them into exported Markdown playbooks. This content is intended to be used in future LLM prompts, creating a surface for indirect prompt injection. However, the skill itself does not execute this data, and the risk is limited to the downstream use of the generated text.
  • Ingestion points: The scripts/manage_playbook.py script accepts external JSON files through the --template argument.
  • Boundary markers: None; the script extracts and aggregates text without using delimiters to isolate untrusted content.
  • Capability inventory: The script is limited to local file system writes; it has no network or code execution capabilities.
  • Sanitization: None; transcript and summary text is used directly from the input JSON without filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 08:27 PM
Security Audit — agent-trust-hub — video-playbook