skills/sonilo-ai/skills/video-to-sfx/Gen Agent Trust Hub

video-to-sfx

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions reference the installation of the sonilo and sonilo-cli packages via official package managers. These are verified vendor resources belonging to the skill author.
  • [COMMAND_EXECUTION]: The skill utilizes the sonilo CLI for local video processing tasks as an alternative to the MCP transport.
  • [DATA_EXFILTRATION]: Video data is transmitted to the official Sonilo API at api.sonilo.com for processing. This interaction is central to the skill's purpose and uses vendor-controlled infrastructure.
  • [PROMPT_INJECTION]: The skill processes data from external video URLs, which represents a potential surface for indirect prompt injection.
  • Ingestion points: The video_url parameter in the video_to_sfx and video_to_video_sfx tools in SKILL.md.
  • Boundary markers: None identified in the instructional content.
  • Capability inventory: The skill has access to the Bash shell and Write file system tools.
  • Sanitization: No specific content validation or sanitization steps are documented for the external data inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:07 AM
Security Audit — agent-trust-hub — video-to-sfx