video-evaluate
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses local Node.js scripts to execute FFmpeg and ffprobe commands via
spawnSyncfor media analysis and frame sampling. - Evidence: Found in
scripts/detect-motion-artifacts.ts,scripts/sample-frames.ts, andscripts/inspect-video.ts. - Note: Subprocess execution is implemented using argument arrays, which is a secure practice to prevent shell injection, and the functionality is central to the skill's purpose.
- [INDIRECT_PROMPT_INJECTION]: The skill assesses external media artifacts and scene manifests, presenting a surface for indirect prompt injection if those artifacts contain adversarial content designed to influence the agent's creative judgment.
- Ingestion points: Media artifacts (video frames) and
scene-manifest.json(spatial continuity data). - Boundary markers: The skill instructions emphasize an "evidence-first" approach and deterministic checks before semantic evaluation, which helps mitigate accidental influence.
- Capability inventory: Local command execution for media processing and file writing for frame sampling.
- Sanitization:
scripts/validate-continuity.tsperforms robust structural and type validation on the input JSON manifest to ensure data integrity.
Audit Metadata