video-analysis

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill mentions installation of the sonilo and sonilo-cli packages via Python and Node.js package managers, which are official resources for the platform.
  • [COMMAND_EXECUTION]: Provides instructions for using the sonilo CLI and curl to interact with the Sonilo API at api.sonilo.com.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it processes untrusted video data to generate text prompts. 1. Ingestion points: Data enters via video_path or video_url parameters. 2. Boundary markers: The skill does not define specific delimiters for the generated prompt output. 3. Capability inventory: The skill uses Bash and the Sonilo MCP tools. 4. Sanitization: There is no mention of content filtering or validation for the analyzed video footage.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 06:11 PM
Security Audit — agent-trust-hub — video-analysis