video-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
subprocess.runmodule to invoke theffmpegbinary inanalyze.pyfor essential media processing tasks. These include retrieving video metadata (_get_video_info), extracting keyframes for visual analysis (_extract_frames), and converting audio tracks for transcription (_transcribe_audio). - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted media files, creating a potential vector for indirect prompt injection.
- Ingestion points: Untrusted data enters the agent context through the
pathargument inanalyze_video, which points to video files processed by the skill. - Boundary markers: There are no explicit delimiters or system instructions used to separate the extracted media content (frames/transcripts) from the agent's instructions, nor are there warnings to the model to ignore embedded instructions in the media.
- Capability inventory: The skill possesses capabilities for subprocess execution (ffmpeg), network communication (POST requests to OpenRouter), and file system writes (saving frames to
output/video-frames). - Sanitization: The skill does not perform sanitization, filtering, or validation on the transcribed audio text or visual frame content before passing it to the downstream LLM.
Audit Metadata