create-video
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.runto call external utilities such asffmpeg,ffprobe, and thenpxpackage runner. The implementation follows secure coding patterns by passing arguments as lists, which prevents shell command injection vulnerabilities.\n- [EXTERNAL_DOWNLOADS]: The skill relies onnpxto execute thehyperframestoolkit, which involves fetching packages from the NPM registry. It also incorporates the GSAP animation library from a public CDN in the generated video compositions.\n- [DYNAMIC_EXECUTION]: The skill dynamically generates HTML and JavaScript files at runtime to define animation timing and visual cues. These files are rendered by the HyperFrames engine to produce the final video output.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied topics and technical content into narration and visuals. (1) Ingestion points: Topic and tone parameters inSKILL.md. (2) Boundary markers: The skill useshtml.escapeto delimit user-controlled content in HTML templates. (3) Capability inventory: Subprocess execution and local file-writing capabilities. (4) Sanitization: The skill consistently applieshtml.escapefor content interpolation andyaml.safe_loadfor configuration data.
Audit Metadata