amc-run-rtsp-calibration
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill handles data from external sources that could contain malicious instructions or unexpected content.\n
- Ingestion points: The skill ingests data from user-provided RTSP URLs, the
STREAMS_JSONenvironment variable, and local calibration files likesettings.jsonandalignment_data.jsonfound in user-specified directories.\n - Boundary markers:
SKILL.mdcontains explicit instructions for the agent to ask the user for required parameters (e.g., URL, camera names, project name) and warns against reusing sample dataset files or settings unless explicitly directed by the user.\n - Capability inventory: The bundled Python script (
run_rtsp_calibration.py) and shell instructions use therequestslibrary andcurlto perform network operations against user-defined service URLs and read local files for API uploads.\n - Sanitization: The script includes a
_redact_rtsp_urlhelper function to remove credentials from URLs before they are printed to the console, and the instructions explicitly advise the agent not to echo tokens or credentials in logs or chat.
Audit Metadata