explainer
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The skill uses a shell script to probe for a sibling dependency (
ofox-video.sh) across several potential file system paths, including hidden directories like~/.agents/skills/, and subsequently executes the found script usingbash. - [COMMAND_EXECUTION]: The skill constructs shell commands that include user-supplied text as an argument for the
--promptflag. This design creates a risk of command injection if the input text contains shell metacharacters that are not properly escaped by the agent before execution. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external content, such as blog posts or documentation, which could contain malicious instructions meant to influence the agent's behavior or the downstream video generation API.
- Ingestion points: Source text (articles, release notes, READMEs) provided by the user as input to the skill.
- Boundary markers: The skill lacks explicit boundary markers or instructions to ignore embedded commands within the ingested source text.
- Capability inventory: The skill possesses capabilities for shell command execution (
bash,curl,jq) and file system write operations through its delegated core skill. - Sanitization: No evidence of input validation, filtering, or escaping was found in the instructions regarding how the external source text is processed.
- [EXTERNAL_DOWNLOADS]: The skill facilitates the download of generated media files from the vendor's API to the local machine, with the destination controlled by the user-provided
--out-dirparameter.
Audit Metadata