create-short
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses subprocess calls to execute system utilities for video and audio processing. These include calling
ffprobefor metadata verification,ffmpegfor loudness analysis and contact sheet generation inscripts/verify_short.py, andnpx hyperframesfor project initialization inscripts/scaffold.py. These calls are implemented using list arguments without shell injection risks and are necessary for the skill's primary function. - [DYNAMIC_EXECUTION]: The skill implements a scaffolding mechanism where
scripts/scaffold.pygenerates a Python composition script (build.py) by interpolating data fromoutline.jsoninto a predefined template. This is a standard architectural pattern for this toolset. The interpolation includes basic sanitization by replacing double quotes to prevent string breakout, which is appropriate for the intended developer-oriented use case. - [EXTERNAL_DOWNLOADS]: The skill references external resources including the author's own GitHub repository (
github.com/mohitmishra786/yt-setup) for shared assets and standard package registries for dependencies likehyperframes(via npx),chatterbox, andfaster_whisper. References to the Linux kernel source on GitHub for verification are also included and target trusted sources. - [SAFE]: The workflow incorporates multiple human-in-the-loop verification gates, such as
voice-checkfor manual review of cloned audio and a snapshot system for reviewing visual beats before final rendering. The inclusion of Docker-based verification for code examples demonstrates a commitment to isolated and reproducible technical verification.
Audit Metadata