video-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the subprocess.run module to invoke the ffmpeg binary in analyze.py for essential media processing tasks. These include retrieving video metadata (_get_video_info), extracting keyframes for visual analysis (_extract_frames), and converting audio tracks for transcription (_transcribe_audio).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted media files, creating a potential vector for indirect prompt injection.
  • Ingestion points: Untrusted data enters the agent context through the path argument in analyze_video, which points to video files processed by the skill.
  • Boundary markers: There are no explicit delimiters or system instructions used to separate the extracted media content (frames/transcripts) from the agent's instructions, nor are there warnings to the model to ignore embedded instructions in the media.
  • Capability inventory: The skill possesses capabilities for subprocess execution (ffmpeg), network communication (POST requests to OpenRouter), and file system writes (saving frames to output/video-frames).
  • Sanitization: The skill does not perform sanitization, filtering, or validation on the transcribed audio text or visual frame content before passing it to the downstream LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 08:08 PM
Security Audit — agent-trust-hub — video-analysis