talking-head-production
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to install the
belt-sh/clitool from the npm registry and references setup documentation hosted on theinference-shGitHub repository. - [COMMAND_EXECUTION]: Employs the
beltCLI to perform authentication and execute remote AI applications for image, audio, and video processing. - [PROMPT_INJECTION]: The skill processes natural language input for video scripts and generation prompts, which constitutes a surface for indirect prompt injection.
- Ingestion points: Processes user-provided strings through the
voice_script,prompt,voice_prompt, andvideo_promptfields inSKILL.md. - Boundary markers: Not utilized in the provided command-line examples.
- Capability inventory: The skill enables remote media generation and application execution via the
belt app runcommand. - Sanitization: No explicit input sanitization or validation is described for the processed text.
Audit Metadata