amc-run-video-calibration

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a bundled Python script (scripts/run_video_calibration.py) to manage the calibration workflow. It uses a bash block in SKILL.md to locate the script across various possible installation paths and invokes it using the local python3 interpreter.
  • [DATA_EXFILTRATION]: The skill transmits local data, including MP4 video files, JSON configuration files, and images, to a user-specified REST API endpoint (BASE_URL). This behavior is the intended and documented primary function of the skill for remote processing of datasets.
  • [INDIRECT_PROMPT_INJECTION]: The skill scans for and processes local configuration files which could influence the agent's workflow.
  • Ingestion points: The VIDEO_DIR and its parent directories are scanned for settings.json, config.json, and alignment_data.json.
  • Boundary markers: No explicit prompt boundaries or "ignore" instructions are used when interpolating file-derived data into the workflow logic.
  • Capability inventory: The skill has file system read access and network transmission capabilities via the requests library.
  • Sanitization: Content from JSON files is parsed using standard libraries, and specific fields (like detector_type) are used to parameterize the API calls.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 08:38 AM
Security Audit — agent-trust-hub — amc-run-video-calibration