ui-recording-timeline

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The Python script executes ffmpeg and ffprobe to extract frames and metadata from video recordings. It also optionally launches a headless browser (Chrome or Chromium) to generate a preview image of the final timeline. These operations are essential for the skill's functionality and are performed using safe subprocess patterns.
  • [EXTERNAL_DOWNLOADS]: The skill uses the uv package manager to handle its Python dependencies, which include standard libraries for image processing and numerical computation such as opencv-python-headless, numpy, scipy, and pillow.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided video files and JSON metadata. The generated interactive timeline includes an HTML template that sanitizes this input data using a dedicated escaping function to mitigate potential cross-site scripting (XSS) risks when rendering labels and notes.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 01:39 AM
Security Audit — agent-trust-hub — ui-recording-timeline