venice
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches generated video content from external URLs in the
video_generatefunction withinexports.py. When a video generation task is completed, the skill retrieves adownload_urlfrom the Venice API response and usesrequests.getto download the media file to the local workspace. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input, such as image prompts, video descriptions, and YouTube URLs, which are then used in network operations and content retrieval tasks.
- Ingestion points: User-provided strings for the
promptparameter in image/video generation and external URLs provided to theimage_edit,image_upscale,video_queue, andvideo_transcribe_youtubefunctions inexports.py. - Boundary markers: The instructions do not define specific boundary markers or use system instructions to isolate user-provided prompts from the agent's core logic.
- Capability inventory: The skill has the ability to perform arbitrary network requests through the
requestslibrary and write files to theoutput/directory on the local filesystem. - Sanitization: There is no evidence of input validation or sanitization for the URLs or prompts before they are interpolated into API requests or used to fetch content.
Audit Metadata