venice

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches generated video content from external URLs in the video_generate function within exports.py. When a video generation task is completed, the skill retrieves a download_url from the Venice API response and uses requests.get to download the media file to the local workspace.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input, such as image prompts, video descriptions, and YouTube URLs, which are then used in network operations and content retrieval tasks.
  • Ingestion points: User-provided strings for the prompt parameter in image/video generation and external URLs provided to the image_edit, image_upscale, video_queue, and video_transcribe_youtube functions in exports.py.
  • Boundary markers: The instructions do not define specific boundary markers or use system instructions to isolate user-provided prompts from the agent's core logic.
  • Capability inventory: The skill has the ability to perform arbitrary network requests through the requests library and write files to the output/ directory on the local filesystem.
  • Sanitization: There is no evidence of input validation or sanitization for the URLs or prompts before they are interpolated into API requests or used to fetch content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — venice