gif-sticker-maker
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user content that is interpolated into generation prompts.
- Ingestion points: User-provided photos via the
--subject-refargument and custom text captions via the{caption}placeholder inSKILL.md. - Boundary markers: The custom caption is enclosed within double quotes (
Caption: "{caption}") insideassets/image-prompt-template.txt. - Capability inventory: The skill invokes local python scripts (
minimax_image.py,minimax_video.py,convert_mp4_to_gif.py) that perform network API requests to MiniMax endpoints and runffmpegvia structured subprocess calls. - Sanitization: There is no input sanitization or filtering performed on the user-supplied captions before interpolation into the prompt template.
- [COMMAND_EXECUTION]: The script
scripts/convert_mp4_to_gif.pyexecutes theffmpegbinary usingsubprocess.run(). This execution is securely constructed using an argument list rather than a shell string, preventing shell command injection vectors.
Audit Metadata