talking-head
Warn
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill employs a shell-based probe to find the
ofox-video-coredependency across multiple possible local directories (such as~/.agents/skills/ofox-video-coreor relative paths like../ofoxai-skills-ofox-video-core). It then executes theofox-video.shscript from the resolved path. Loading and executing scripts from non-static, computed paths at runtime is a risk factor. - Evidence: Found in
SKILL.mdwithin theWhere the core skill livessection, which defines a loop to find the script and uses the result for subsequentbashcalls. - [INDIRECT_PROMPT_INJECTION]: The skill integrates untrusted user input—specifically a portrait image and a text script—directly into a complex prompt for AI video generation. The instructions require the user's script to be quoted "verbatim and untranslated," which could allow an attacker to include hidden instructions to manipulate the video output or model behavior.
- Evidence:
SKILL.mdprompt template section, using placeholders like<the script, verbatim, in the language to be spoken>. - Ingestion points: User-supplied portrait image and text script (SKILL.md).
- Boundary markers: The prompt uses quotes for the script and specific section labels (IDENTITY, SCENE, FRAMING) to delimit content.
- Capability inventory: File system read (portrait), file system write (video output/sidecars), and network operations via
curltoapp.ofox.ai(managed by the core script). - Sanitization: No sanitization or escaping of the user-provided script is mentioned; the skill prioritizes verbatim usage.
- [REMOTE_CODE_EXECUTION]: The skill provides instructions for the user to install the core dependency via
npxcommands if the script is not found locally. While these target the vendor's own repository, they involve downloading and executing external code. - Evidence:
SKILL.md("If the script isn't found" section) andCHANGELOG.md(version 1.1.1). - [COMMAND_EXECUTION]: The skill relies on shell command execution via
bashto interact with the coreofox-video.shutility for critical functions such as model availability checks, pricing estimates (--dry-run), and actual job submission (--approved). - Evidence: Multiple code blocks in
SKILL.mddemonstratingbash ../ofox-video-core/references/ofox-video.sh generate ...and other subcommands.
Audit Metadata