video-explainer
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple local JavaScript and shell commands to manage the video production pipeline.
- Orchestrates local scripts such as
scripts/video-explainer.mjsandscripts/verify-shorts.mjsfor diagnostics, review, rendering, and verification. - Utilizes system tools like
ffmpegandffprobefor media processing.- [EXTERNAL_DOWNLOADS]: The installation process involves downloading external resources from the vendor repository. - Fetches the
claude-video-kitfrom the author's GitHub repository usingnpx skills addand installs dependencies vianpm ci.- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it processes external research briefs into executable video scripts. - Ingestion point: The
script.jsongeneration process inbrief-to-script.mdaccepts research briefs or scripts from the agent context. - Boundary markers: The skill implements a mandatory 'review gate' workflow defined in
review-gate.md, which requires an independent review and a SHA-256 bound receipt before rendering is permitted. - Capability inventory: The skill calls subprocesses for video rendering and verification via local scripts.
- Sanitization: The manual/independent review receipt serves as the primary validation step for untrusted content.
Audit Metadata