mmx-cli
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill enables the agent to process untrusted external content, creating an attack surface for indirect prompt injection.\n
- Ingestion points: Untrusted data is ingested via
vision describe(images/URLs),speech transcribe(audio files), andsearch query(web results) inSKILL.md.\n - Boundary markers: No specific delimiters or instructions are provided to the agent to disregard instructions within these external inputs.\n
- Capability inventory: The skill possesses capabilities for reading local files, writing files, and communicating with external APIs.\n
- Sanitization: No sanitization of ingested content is defined in the instructions.\n- [DATA_EXFILTRATION]: The skill provides the capability to read local files and transmit their contents to the MiniMax API for processing, which constitutes a potential data exfiltration vector if the agent is misdirected.\n- [DYNAMIC_EXECUTION]: In
h3-video/SKILL.md, the skill directs the agent to build local project artifacts usingbun run buildand execute them vianode ./dist/mmx.mjs, which involves the execution of runtime-compiled code.\n- [CREDENTIALS_UNSAFE]: The skill manages MiniMax API keys and persists them in the~/.mmx/config.jsonconfiguration file as part of its authentication workflow.\n- [EXTERNAL_DOWNLOADS]: The skill documentation references the installation of themmx-clipackage from the npm registry to provide its core functionality.
Audit Metadata