ai-content-pipeline

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an external URL (raw.githubusercontent.com/inference-sh/skills/refs/heads/main/cli-install.md) to provide installation instructions for the required CLI tool.
  • [REMOTE_CODE_EXECUTION]: The skill utilizes the belt app run command to trigger execution of various AI models (e.g., Claude, FLUX, Kokoro) on the inference.sh remote platform.
  • [COMMAND_EXECUTION]: The skill defines complex automation workflows that rely on executing the belt CLI via the shell to manage authentication, application execution, and file output management.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from blog posts or user-defined topics to generate scripts and visual assets. 1. Ingestion points: SKILL.md (Blog to Video Pipeline section). 2. Boundary markers: Absent; external content is interpolated directly into the model inputs. 3. Capability inventory: The skill uses belt app run for model inference and media-merger for file processing. 4. Sanitization: Absent; the skill assumes the underlying AI models or platform will handle content safety.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:21 PM
Security Audit — agent-trust-hub — ai-content-pipeline