replace-in-video

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements video element swapping using verified vendor models, specifically prunaai:p-video@replace and bytedance:seedance@2.0. All processing occurs through standard asynchronous task workflows.
  • [DATA_EXFILTRATION]: The skill transmits media data to vm.runware.ai for inference. This is a recognized vendor domain for the author 'runware' and is essential for the functionality of the video-to-video service. No exfiltration to unknown or third-party domains is present.
  • [PROMPT_INJECTION]: While the skill ingests user-provided text prompts to identify objects for replacement, it provides structured templates that help delineate user input from system instructions. No patterns of safety bypass or role-play injection were found.
  • [COMMAND_EXECUTION]: The instructions and examples involve the use of platform-standard commands like runware-run and runware-models. No evidence of arbitrary shell execution, privilege escalation, or persistence mechanisms was identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 04:08 PM
Security Audit — agent-trust-hub — replace-in-video