video-extend-edit

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes standard system binaries (ffmpeg, ffprobe, curl, jq) to perform local video processing tasks such as frame extraction, duration calculation, and video concatenation. These commands are executed via a local shell script provided by the vendor.
  • [INDIRECT_PROMPT_INJECTION]: As the skill ingests and processes user-supplied video files, it technically possesses an attack surface for indirect injection via visual content (steganography or embedded text). However, the risk is minimized as the skill uses the video frames purely as visual references for scene continuity and follows a strict approval-based generation flow.
  • Ingestion points: User-provided video files (passed as file paths to CLI arguments).
  • Boundary markers: The prompt template uses explicit sections (CONTINUES FROM, ACTION, CAMERA, ENDING, AVOID) to delimit instructions from data references.
  • Capability inventory: File system access, local video processing via ffmpeg, and network communication with the vendor API.
  • Sanitization: The skill relies on local binaries for extraction, which act as a layer of processing before any data is sent to the LLM or API.
  • [EXTERNAL_DOWNLOADS]: The skill communicates with the ofox.ai domain to submit video generation jobs. This is the intended primary function of the skill and uses the vendor's official infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:58 AM