video-creator

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: Executes shell commands for project orchestration, including npx create-video for initial scaffolding and npx remotion render for the final 4K video production.
  • [COMMAND_EXECUTION]: Probes the local environment by running ls on standard AI agent skill directories to identify and recommend missing companion skills to the user.
  • [EXTERNAL_DOWNLOADS]: Fetches project templates and dependencies from the npm registry and communicates with the official ElevenLabs API for narration audio generation.
  • [REMOTE_CODE_EXECUTION]: Uses npx to fetch and execute remote project templates and dynamically generates React-based video compositions from user-provided script data.
  • [SAFE]: Processes untrusted data from user interviews to populate a YAML-based script that drives automated code generation; this surface is mitigated by mandatory human-in-the-loop approval gates before code is finalized or external API costs are incurred.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 03:05 PM
Security Audit — agent-trust-hub — video-creator