amazon-research

Pass

Audited by Gen Agent Trust Hub on May 13, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The script _postplus_shared/00-core/shared-runtime/scripts/download_videos_from_manifest_with_ytdlp.mjs uses child_process.spawn to execute yt_dlp for media processing. This is a controlled execution of a well-known tool for downloading and merging product video content. The execution is scoped to the skill's intended functionality of processing marketplace media.\n- [SAFE]: The skill manages session authentication and API configuration using files in the user's home directory (e.g., ~/.config/postplus), following standard developer tool patterns for CLI-based agent extensions and session persistence.\n- [SAFE]: Network requests are routed through a dedicated runtime that communicates with the vendor's cloud infrastructure for hosted collection and billing, with no evidence of unauthorized data transmission or suspicious external connections.
Audit Metadata
Risk Level
SAFE
Analyzed
May 13, 2026, 07:53 PM