showcase-video

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill documentation describes the use of a custom CLI toolchain (um) to perform system-level tasks. These include recording specific game windows (um win record), performing file system operations (um backup), and capturing audio via a PowerShell loopback script (tools/win/ProcLoopback.ps1).- [INDIRECT_PROMPT_INJECTION]: The skill processes Edit Decision List (EDL) JSON files and external video clips, which serve as ingestion points for untrusted content. 1. Ingestion points: edl.json configuration files and external .mp4 video files. 2. Boundary markers: No specific delimiters or warnings for embedded instructions are mentioned. 3. Capability inventory: The skill uses the um toolchain to process these files and render titles or hooks onto video frames using ffmpeg. 4. Sanitization: No sanitization is mentioned for text fields processed from the EDL JSON.- [EXTERNAL_DOWNLOADS]: The skill instructions suggest downloading public clips and posts from external sources when creating video compilations.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 03:56 PM
Security Audit — agent-trust-hub — showcase-video