video

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The instructions in SKILL.md direct the agent to load and run internal Python scripts using exec(open(...).read()). This pattern is used to execute the skill's own functional scripts (generate_video.py, publish_asset.py) within a Python environment initialized via a bash heredoc.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to handle user-supplied text prompts and image/video URLs which are subsequently processed by external APIs and file management scripts.
  • Ingestion points: User prompts and reference asset URLs ingested by generate_video() and publish_asset.py through agent commands.
  • Boundary markers: No specific boundary markers or 'ignore' instructions are present in the scripts to delimit untrusted data from system instructions.
  • Capability inventory: The skill possesses the capability to perform network operations (POST/GET via requests), write files to the output/videos directory, and copy local files into the output/fal_assets directory.
  • Sanitization: publish_asset.py includes a validation check against a list of allowed extensions (.jpg, .mp4, etc.), which prevents the skill from accidentally exposing sensitive system configuration files (like .env) when hosting assets for the external video API.
  • [EXTERNAL_DOWNLOADS]: The skill performs network downloads to fetch generated video content from fal.media (a recognized video service) and permits the download of media assets from arbitrary external URLs specified by the user in publish_asset.py.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — video