viral-short-video
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches video assets from YouTube for use as background footage and reference hooks using
yt-dlpinscripts/download_assets.sh. These downloads target a well-known service and are used for their intended purpose as video assets. - [COMMAND_EXECUTION]: The main script
scripts/generate_viral_script.pyusessubprocess.run()to invoke helper scripts for keyframe extraction and storyboard generation. These calls use argument lists rather than shell strings, following security best practices for internal tool execution. - [PROMPT_INJECTION]: The skill processes untrusted user inputs (topic, target, and character descriptions) in
scripts/generate_viral_script.pythat are interpolated into prompts without boundary markers or sanitization. The skill allows the agent to execute sub-processes and interact with external APIs, which represents a potential surface for indirect prompt injection.
Audit Metadata