ai-multimodal
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/media_optimizer.pyuses theeval()function to parse frame rate metadata (r_frame_rate) extracted byffprobe. Because this metadata originates from potentially untrusted media files, an attacker could craft a malicious file that executes arbitrary Python code when processed. - [COMMAND_EXECUTION]: The skill executes external system commands using
subprocess.run. Specifically,scripts/media_optimizer.pycallsffmpegandffprobeto process media, andscripts/document_converter.pyuses shell commands for document conversion tasks. - [INDIRECT_PROMPT_INJECTION]: The skill processes various external media formats (PDF, audio, video, images) which may contain embedded malicious instructions. Since the agent is granted powerful tools like
BashandEdit, a successful indirect injection could lead to unauthorized actions. Ingestion points: untrusted media files processed ingemini_batch_process.pyanddocument_converter.py. Boundary markers: absent. Capability inventory:Bash,Write, andEdittools enabled; subprocess calls in Python scripts. Sanitization: no explicit filtering or instruction-stripping for media content. - [SAFE]: The skill implements a hierarchical search for the
GEMINI_API_KEYacross various.envfiles. This follows standard secret management practices for local development environments and does not constitute a security risk.
Audit Metadata