subtitle-packager

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs subtitle packaging tasks, including chunking normalized transcripts and generating timed artifacts (SRT, VTT, ASS), which aligns with its stated purpose.
  • [CREDENTIALS_UNSAFE]: The library script postplus_cli_config.mjs accesses local configuration files in the user's application data directory to retrieve session tokens. This is used exclusively for authenticating with the vendor's own cloud API services.
  • [COMMAND_EXECUTION]: The shared utility download_videos_from_manifest_with_ytdlp.mjs executes yt-dlp via a subprocess to retrieve media files for processing.
  • [EXTERNAL_DOWNLOADS]: The skill's shared runtime handles network communication with the author's API and cloud storage for hosted media generation and file transfers.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 07:44 AM
Security Audit — agent-trust-hub — subtitle-packager