video-explainer

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes multiple local JavaScript and shell commands to manage the video production pipeline.
  • Orchestrates local scripts such as scripts/video-explainer.mjs and scripts/verify-shorts.mjs for diagnostics, review, rendering, and verification.
  • Utilizes system tools like ffmpeg and ffprobe for media processing.- [EXTERNAL_DOWNLOADS]: The installation process involves downloading external resources from the vendor repository.
  • Fetches the claude-video-kit from the author's GitHub repository using npx skills add and installs dependencies via npm ci.- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it processes external research briefs into executable video scripts.
  • Ingestion point: The script.json generation process in brief-to-script.md accepts research briefs or scripts from the agent context.
  • Boundary markers: The skill implements a mandatory 'review gate' workflow defined in review-gate.md, which requires an independent review and a SHA-256 bound receipt before rendering is permitted.
  • Capability inventory: The skill calls subprocesses for video rendering and verification via local scripts.
  • Sanitization: The manual/independent review receipt serves as the primary validation step for untrusted content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 12:11 AM