viral-short-video

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches video assets from YouTube for use as background footage and reference hooks using yt-dlp in scripts/download_assets.sh. These downloads target a well-known service and are used for their intended purpose as video assets.
  • [COMMAND_EXECUTION]: The main script scripts/generate_viral_script.py uses subprocess.run() to invoke helper scripts for keyframe extraction and storyboard generation. These calls use argument lists rather than shell strings, following security best practices for internal tool execution.
  • [PROMPT_INJECTION]: The skill processes untrusted user inputs (topic, target, and character descriptions) in scripts/generate_viral_script.py that are interpolated into prompts without boundary markers or sanitization. The skill allows the agent to execute sub-processes and interact with external APIs, which represents a potential surface for indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 08:27 PM
Security Audit — agent-trust-hub — viral-short-video