video-translation
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary workflow involves downloading and processing subtitle files (SRT) from external URLs. These files are then passed directly into a translation prompt for the AI to process.
- Ingestion points: Subtitles are fetched via
youtube-downloaderand stored in/tmp/video-translationbefore being read as text (SKILL.md, Workflow step 2). - Boundary markers: The skill uses a specific 'Translation Prompt' to guide the LLM, but it lacks strict XML-style delimiters or explicit instructions to ignore control sequences potentially embedded in the subtitle text.
- Capability inventory: The skill has access to shell execution (
ffmpeg,bashscripts) and file system writes. If a malicious subtitle file successfully injects commands that influence the agent's next steps, it could lead to unauthorized file manipulation. - Sanitization: There is no evidence of sanitization or validation of the subtitle content before it is sent to the LLM for translation.
- [EXTERNAL_DOWNLOADS]: The requirements section instructs the user or agent to clone/copy external skills from GitHub repositories (
github.com/crazynomad/skillsandgithub.com/NoizAI/skills) to fulfill dependencies likeyoutube-downloaderandtts. These are documented neutrally as required resources for the skill's functionality.
Audit Metadata