media-processing
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Python
subprocessmodule to execute system binaries for media processing tasks. - Evidence: Found in
scripts/media_convert.py,scripts/batch_resize.py, andscripts/video_optimize.pywhere the scripts invokeffmpeg,ffprobe, andmagick. - Note: Commands are executed using argument lists, which is a recommended security practice to prevent shell injection vulnerabilities.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external media files, which represents a potential surface for indirect prompt injection through malicious file metadata or specially crafted filenames.
- Ingestion points:
scripts/batch_resize.py,scripts/media_convert.py, andscripts/video_optimize.pyaccept file paths as input. - Boundary markers: The skill does not implement explicit boundary markers for untrusted data.
- Capability inventory: The skill has the capability to write to the local file system and execute subprocesses.
- Sanitization: The implementation uses
pathlib.Pathobjects and list-based subprocess execution, which significantly reduces the risk of traditional command injection.
Audit Metadata