ai-multimodal

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/media_optimizer.py uses the eval() function to parse frame rate metadata (r_frame_rate) extracted by ffprobe. Because this metadata originates from potentially untrusted media files, an attacker could craft a malicious file that executes arbitrary Python code when processed.
  • [COMMAND_EXECUTION]: The skill executes external system commands using subprocess.run. Specifically, scripts/media_optimizer.py calls ffmpeg and ffprobe to process media, and scripts/document_converter.py uses shell commands for document conversion tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes various external media formats (PDF, audio, video, images) which may contain embedded malicious instructions. Since the agent is granted powerful tools like Bash and Edit, a successful indirect injection could lead to unauthorized actions. Ingestion points: untrusted media files processed in gemini_batch_process.py and document_converter.py. Boundary markers: absent. Capability inventory: Bash, Write, and Edit tools enabled; subprocess calls in Python scripts. Sanitization: no explicit filtering or instruction-stripping for media content.
  • [SAFE]: The skill implements a hierarchical search for the GEMINI_API_KEY across various .env files. This follows standard secret management practices for local development environments and does not constitute a security risk.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 10:08 PM
Security Audit — agent-trust-hub — ai-multimodal