create-video

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to call external utilities such as ffmpeg, ffprobe, and the npx package runner. The implementation follows secure coding patterns by passing arguments as lists, which prevents shell command injection vulnerabilities.\n- [EXTERNAL_DOWNLOADS]: The skill relies on npx to execute the hyperframes toolkit, which involves fetching packages from the NPM registry. It also incorporates the GSAP animation library from a public CDN in the generated video compositions.\n- [DYNAMIC_EXECUTION]: The skill dynamically generates HTML and JavaScript files at runtime to define animation timing and visual cues. These files are rendered by the HyperFrames engine to produce the final video output.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied topics and technical content into narration and visuals. (1) Ingestion points: Topic and tone parameters in SKILL.md. (2) Boundary markers: The skill uses html.escape to delimit user-controlled content in HTML templates. (3) Capability inventory: Subprocess execution and local file-writing capabilities. (4) Sanitization: The skill consistently applies html.escape for content interpolation and yaml.safe_load for configuration data.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 07:36 PM
Security Audit — agent-trust-hub — create-video