ai-multimodal
Warn
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/media_optimizer.pyutilizes theeval()function to calculate frame rates (e.g., parsing "30/1") fromffprobeoutput. Since this data is derived from the metadata of untrusted media files, it presents a potential security risk for arbitrary code execution if the metadata is maliciously manipulated.\n- [COMMAND_EXECUTION]: The skill usessubprocess.run()inscripts/media_optimizer.pyto invoke external system utilitiesffmpegandffprobefor media processing. While arguments are passed as a list to mitigate shell injection, the execution of complex external binaries on untrusted files increases the system's attack surface.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content such as PDFs and videos and feeds it to the AI model. Maliciously crafted media could contain instructions designed to manipulate the agent's behavior after the data is processed into the context.\n - Ingestion points:
scripts/document_converter.pyandscripts/gemini_batch_process.py(via media upload).\n - Boundary markers: Prompts used for conversion do not implement robust data/instruction separation.\n
- Capability inventory: The agent has
Bash,Write, andEditpermissions.\n - Sanitization: Content extracted from media is not sanitized before being presented to the agent.\n- [DATA_EXFILTRATION]: Transmits local media files to Google's official Gemini API (ai.google.dev) for processing. While this is the intended purpose, users should be aware that local data is shared with a cloud service.
Audit Metadata