riffkit

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill requires the agent to handle a vee_session token for authentication. While the documentation provides instructions to keep this token out of logs and output, the presence of session-level credentials within the agent's working context is a sensitive operation that increases the risk of accidental exposure.\n- [COMMAND_EXECUTION]: The skill instructions direct the agent to perform network-based API calls to https://riffkit.ai for video rendering and task monitoring. These actions can incur financial costs, making the workflow dependent on strict adherence to the provided confirmation steps.\n- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by ingesting and analyzing untrusted external content from TikTok URLs and uploaded videos.\n
  • Ingestion points: External TikTok URLs and video files are directly processed through the workflow (SKILL.md).\n
  • Boundary markers: There are no explicit instructions or delimiters defined to isolate or ignore instructions that might be embedded within the metadata or content of the retrieved video sources.\n
  • Capability inventory: The agent possesses the capability to perform authenticated network requests and initiate billable API calls based on the analysis of these external inputs.\n
  • Sanitization: The skill does not specify any sanitization, validation, or filtering steps for the data extracted from the external source videos.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 04:43 PM
Security Audit — agent-trust-hub — riffkit