videodb-skills

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires installing the 'videodb' package and 'python-dotenv' from PyPI, as well as a skill package via npx. These represent standard dependencies for interacting with the VideoDB platform.
  • [COMMAND_EXECUTION]: Setup instructions include shell commands for package installation and environment variable configuration, which are routine for developer tools and do not involve suspicious behavior.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it processes external video transcripts. 1. Ingestion points: External URLs and local files (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Video editing, AI generation, and real-time capture (SKILL.md). 4. Sanitization: Not specified in the instructions. This is a common characteristic of media-processing skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 01:39 AM