videoagent-director
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-originated creative briefs to generate prompts and parameters for media production tools, creating a vulnerability surface.
- Ingestion points: User-provided video concepts, briefs, and image URLs are ingested by the creative director instructions in SKILL.md.
- Boundary markers: Absent; the instructions do not implement delimiters or explicit warnings to ignore instructions embedded within the user's brief.
- Capability inventory: The skill executes local shell commands via
tools/director.jsand performs network POST requests to external proxy endpoints. - Sanitization: No specific validation, escaping, or filtering logic is present in the
director.jsscript to sanitize user-originated content before it is passed to tool arguments. - [EXTERNAL_DOWNLOADS]: The skill interacts with remote services to manage the generation pipeline.
- Findings: Fetches session tokens and generation results from vendor-managed proxies hosted on Vercel (such as
pexo-video-deploy.vercel.app). These network operations are core to the skill's "API key-free" design and are documented in the README. - [COMMAND_EXECUTION]: The skill utilizes a local utility script to handle shot execution.
- Findings: The agent is instructed to invoke
tools/director.jswith structured CLI arguments for each shot. The script uses Node.js standard libraries to manage these operations safely within its defined scope.
Audit Metadata