media-processing

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes Python scripts (batch_resize.py, media_convert.py, video_optimize.py) that invoke external system binaries including ffmpeg, ffprobe, and magick.
  • Evidence: The scripts use subprocess.run() to execute these tools for media processing tasks.
  • Mitigation: The implementation uses list-based arguments for all subprocess calls rather than passing raw strings to a shell (shell=True is not used). This is a standard security best practice that prevents shell command injection even when processing user-provided file paths or parameters.
  • Context: These executions are essential for the primary functionality of a media processing skill and are implemented safely.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:39 AM
Security Audit — agent-trust-hub — media-processing