media-processing

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Python subprocess module to execute system binaries for media processing tasks.
  • Evidence: Found in scripts/media_convert.py, scripts/batch_resize.py, and scripts/video_optimize.py where the scripts invoke ffmpeg, ffprobe, and magick.
  • Note: Commands are executed using argument lists, which is a recommended security practice to prevent shell injection vulnerabilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external media files, which represents a potential surface for indirect prompt injection through malicious file metadata or specially crafted filenames.
  • Ingestion points: scripts/batch_resize.py, scripts/media_convert.py, and scripts/video_optimize.py accept file paths as input.
  • Boundary markers: The skill does not implement explicit boundary markers for untrusted data.
  • Capability inventory: The skill has the capability to write to the local file system and execute subprocesses.
  • Sanitization: The implementation uses pathlib.Path objects and list-based subprocess execution, which significantly reduces the risk of traditional command injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:05 AM
Security Audit — agent-trust-hub — media-processing