video
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The instructions in
SKILL.mddirect the agent to load and run internal Python scripts usingexec(open(...).read()). This pattern is used to execute the skill's own functional scripts (generate_video.py,publish_asset.py) within a Python environment initialized via a bash heredoc. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to handle user-supplied text prompts and image/video URLs which are subsequently processed by external APIs and file management scripts.
- Ingestion points: User prompts and reference asset URLs ingested by
generate_video()andpublish_asset.pythrough agent commands. - Boundary markers: No specific boundary markers or 'ignore' instructions are present in the scripts to delimit untrusted data from system instructions.
- Capability inventory: The skill possesses the capability to perform network operations (POST/GET via
requests), write files to theoutput/videosdirectory, and copy local files into theoutput/fal_assetsdirectory. - Sanitization:
publish_asset.pyincludes a validation check against a list of allowed extensions (.jpg,.mp4, etc.), which prevents the skill from accidentally exposing sensitive system configuration files (like.env) when hosting assets for the external video API. - [EXTERNAL_DOWNLOADS]: The skill performs network downloads to fetch generated video content from
fal.media(a recognized video service) and permits the download of media assets from arbitrary external URLs specified by the user inpublish_asset.py.
Audit Metadata