create-short

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess calls to execute system utilities for video and audio processing. These include calling ffprobe for metadata verification, ffmpeg for loudness analysis and contact sheet generation in scripts/verify_short.py, and npx hyperframes for project initialization in scripts/scaffold.py. These calls are implemented using list arguments without shell injection risks and are necessary for the skill's primary function.
  • [DYNAMIC_EXECUTION]: The skill implements a scaffolding mechanism where scripts/scaffold.py generates a Python composition script (build.py) by interpolating data from outline.json into a predefined template. This is a standard architectural pattern for this toolset. The interpolation includes basic sanitization by replacing double quotes to prevent string breakout, which is appropriate for the intended developer-oriented use case.
  • [EXTERNAL_DOWNLOADS]: The skill references external resources including the author's own GitHub repository (github.com/mohitmishra786/yt-setup) for shared assets and standard package registries for dependencies like hyperframes (via npx), chatterbox, and faster_whisper. References to the Linux kernel source on GitHub for verification are also included and target trusted sources.
  • [SAFE]: The workflow incorporates multiple human-in-the-loop verification gates, such as voice-check for manual review of cloned audio and a snapshot system for reviewing visual beats before final rendering. The inclusion of Docker-based verification for code examples demonstrates a commitment to isolated and reproducible technical verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 07:36 PM
Security Audit — agent-trust-hub — create-short