video-production

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses specialized TypeScript scripts (scripts/inspect-media.ts, scripts/make-contact-sheet.ts, scripts/render-timeline.ts) to execute local system binaries including ffmpeg, ffprobe, and ImageMagick (magick/montage). These operations are used for media inspection, contact sheet generation, and video mastering. The scripts use argument arrays with spawnSync to mitigate command injection risks.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill integrates with external video generation platforms, specifically referencing Replicate and fal.ai as providers for generating video content based on production artifacts. These are established services in the generative media domain.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided briefs and content generated by external AI models to drive its multi-stage production workflow, creating a surface for indirect instructions to influence the pipeline.
  • Ingestion points: User-provided briefs (SKILL.md), timeline JSON data (scripts/render-timeline.ts), and video model outputs from Replicate and fal.ai.
  • Boundary markers: No explicit delimiters or specific 'ignore' instructions for embedded data were identified in the workflow documentation.
  • Capability inventory: The skill utilizes specialized TypeScript scripts to execute local media processing tools and interacts with external generation APIs.
  • Sanitization: The render-timeline.ts script implements validation for numeric parameters such as dimensions, frame rates, and timestamps.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 09:37 PM
Security Audit — agent-trust-hub — video-production