watch

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the subprocess module to invoke local binaries including ffmpeg, ffprobe, and yt-dlp for media processing. All commands are executed with list-based arguments to prevent shell injection, and the operations are strictly aligned with the skill's primary purpose.
  • [EXTERNAL_DOWNLOADS]: The skill downloads video metadata, subtitles, and media files from user-provided URLs using yt-dlp. It also performs audio transcription by sending data to well-known providers (Groq and OpenAI) only when necessary and with explicit user configuration.
  • [CREDENTIALS_UNSAFE]: API keys for transcription services are managed securely. The skill scaffolds a .env file in the user's home directory (~/.config/watch/.env) and explicitly sets file permissions to 0600 (read/write by owner only), which is the standard best practice for local secret storage.
  • [SAFE]: The skill documentation and metadata are consistent with its actual implementation. It provides clear setup instructions and does not employ any obfuscation, persistence, or privilege escalation techniques.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 01:13 PM