amc-run-rtsp-calibration

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill handles data from external sources that could contain malicious instructions or unexpected content.\n
  • Ingestion points: The skill ingests data from user-provided RTSP URLs, the STREAMS_JSON environment variable, and local calibration files like settings.json and alignment_data.json found in user-specified directories.\n
  • Boundary markers: SKILL.md contains explicit instructions for the agent to ask the user for required parameters (e.g., URL, camera names, project name) and warns against reusing sample dataset files or settings unless explicitly directed by the user.\n
  • Capability inventory: The bundled Python script (run_rtsp_calibration.py) and shell instructions use the requests library and curl to perform network operations against user-defined service URLs and read local files for API uploads.\n
  • Sanitization: The script includes a _redact_rtsp_url helper function to remove credentials from URLs before they are printed to the console, and the instructions explicitly advise the agent not to echo tokens or credentials in logs or chat.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 08:39 AM
Security Audit — agent-trust-hub — amc-run-rtsp-calibration