zynna-recreate-video

Pass

Audited by Gen Agent Trust Hub on Apr 17, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests external video data including transcripts and scene descriptions which are stored as local artifacts for further processing. This content could be used as a vector for indirect prompt injection. * Ingestion points: lib/analyze-video.js. * Boundary markers: None identified. * Capability inventory: File writes and network requests. * Sanitization: Raw external data is stored without sanitization.
  • [DATA_EXFILTRATION]: The skill reads API keys from ~/.zynna/credentials.json. While this is standard for its intended use, it involves access to a sensitive credential path.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 17, 2026, 03:52 AM
Security Audit — agent-trust-hub — zynna-recreate-video