video-evaluate

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses local Node.js scripts to execute FFmpeg and ffprobe commands via spawnSync for media analysis and frame sampling.
  • Evidence: Found in scripts/detect-motion-artifacts.ts, scripts/sample-frames.ts, and scripts/inspect-video.ts.
  • Note: Subprocess execution is implemented using argument arrays, which is a secure practice to prevent shell injection, and the functionality is central to the skill's purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill assesses external media artifacts and scene manifests, presenting a surface for indirect prompt injection if those artifacts contain adversarial content designed to influence the agent's creative judgment.
  • Ingestion points: Media artifacts (video frames) and scene-manifest.json (spatial continuity data).
  • Boundary markers: The skill instructions emphasize an "evidence-first" approach and deterministic checks before semantic evaluation, which helps mitigate accidental influence.
  • Capability inventory: Local command execution for media processing and file writing for frame sampling.
  • Sanitization: scripts/validate-continuity.ts performs robust structural and type validation on the input JSON manifest to ensure data integrity.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 08:07 AM
Security Audit — agent-trust-hub — video-evaluate