heygen-video
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides an instruction to execute a local bash script located at
${SKILL_DIR}/scripts/update-check.sh. This script is intended for manual update checks and requires theBashtool to run. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted user data to construct prompts for the HeyGen Video Agent.
- Ingestion points: User-provided
topic_or_scriptarguments, conversational Discovery inputs, and content analyzed from external assets/URLs. - Boundary markers: Employs structural delimiters such as 'CRITICAL ON-SCREEN TEXT' blocks and 'Style blocks' to separate components of the prompt.
- Capability inventory: Uses the
mcp__heygen__*toolset and theheygenCLI to perform video generation and asset management. - Sanitization: Relies on specific framing directives (e.g., 'This script is a concept and theme to convey') to guide the external AI, but lacks explicit sanitization or filtering of the user's input text.
Audit Metadata