watch
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
subprocessmodule to invoke local binaries includingffmpeg,ffprobe, andyt-dlpfor media processing. All commands are executed with list-based arguments to prevent shell injection, and the operations are strictly aligned with the skill's primary purpose. - [EXTERNAL_DOWNLOADS]: The skill downloads video metadata, subtitles, and media files from user-provided URLs using
yt-dlp. It also performs audio transcription by sending data to well-known providers (Groq and OpenAI) only when necessary and with explicit user configuration. - [CREDENTIALS_UNSAFE]: API keys for transcription services are managed securely. The skill scaffolds a
.envfile in the user's home directory (~/.config/watch/.env) and explicitly sets file permissions to0600(read/write by owner only), which is the standard best practice for local secret storage. - [SAFE]: The skill documentation and metadata are consistent with its actual implementation. It provides clear setup instructions and does not employ any obfuscation, persistence, or privilege escalation techniques.
Audit Metadata