skills/ofoxai/skills/talking-head/Gen Agent Trust Hub

talking-head

Warn

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill employs a shell-based probe to find the ofox-video-core dependency across multiple possible local directories (such as ~/.agents/skills/ofox-video-core or relative paths like ../ofoxai-skills-ofox-video-core). It then executes the ofox-video.sh script from the resolved path. Loading and executing scripts from non-static, computed paths at runtime is a risk factor.
  • Evidence: Found in SKILL.md within the Where the core skill lives section, which defines a loop to find the script and uses the result for subsequent bash calls.
  • [INDIRECT_PROMPT_INJECTION]: The skill integrates untrusted user input—specifically a portrait image and a text script—directly into a complex prompt for AI video generation. The instructions require the user's script to be quoted "verbatim and untranslated," which could allow an attacker to include hidden instructions to manipulate the video output or model behavior.
  • Evidence: SKILL.md prompt template section, using placeholders like <the script, verbatim, in the language to be spoken>.
  • Ingestion points: User-supplied portrait image and text script (SKILL.md).
  • Boundary markers: The prompt uses quotes for the script and specific section labels (IDENTITY, SCENE, FRAMING) to delimit content.
  • Capability inventory: File system read (portrait), file system write (video output/sidecars), and network operations via curl to app.ofox.ai (managed by the core script).
  • Sanitization: No sanitization or escaping of the user-provided script is mentioned; the skill prioritizes verbatim usage.
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions for the user to install the core dependency via npx commands if the script is not found locally. While these target the vendor's own repository, they involve downloading and executing external code.
  • Evidence: SKILL.md ("If the script isn't found" section) and CHANGELOG.md (version 1.1.1).
  • [COMMAND_EXECUTION]: The skill relies on shell command execution via bash to interact with the core ofox-video.sh utility for critical functions such as model availability checks, pricing estimates (--dry-run), and actual job submission (--approved).
  • Evidence: Multiple code blocks in SKILL.md demonstrating bash ../ofox-video-core/references/ofox-video.sh generate ... and other subcommands.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 22, 2026, 08:46 AM