ai-multimodal

Warn

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/media_optimizer.py utilizes the eval() function to calculate frame rates (e.g., parsing "30/1") from ffprobe output. Since this data is derived from the metadata of untrusted media files, it presents a potential security risk for arbitrary code execution if the metadata is maliciously manipulated.\n- [COMMAND_EXECUTION]: The skill uses subprocess.run() in scripts/media_optimizer.py to invoke external system utilities ffmpeg and ffprobe for media processing. While arguments are passed as a list to mitigate shell injection, the execution of complex external binaries on untrusted files increases the system's attack surface.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content such as PDFs and videos and feeds it to the AI model. Maliciously crafted media could contain instructions designed to manipulate the agent's behavior after the data is processed into the context.\n
  • Ingestion points: scripts/document_converter.py and scripts/gemini_batch_process.py (via media upload).\n
  • Boundary markers: Prompts used for conversion do not implement robust data/instruction separation.\n
  • Capability inventory: The agent has Bash, Write, and Edit permissions.\n
  • Sanitization: Content extracted from media is not sanitized before being presented to the agent.\n- [DATA_EXFILTRATION]: Transmits local media files to Google's official Gemini API (ai.google.dev) for processing. While this is the intended purpose, users should be aware that local data is shared with a cloud service.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 23, 2026, 05:06 PM
Security Audit — agent-trust-hub — ai-multimodal