image-to-video

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references installation instructions hosted on a public GitHub repository belonging to the service provider (github.com/inference-sh/skills). This is standard documentation for the tool described.
  • [COMMAND_EXECUTION]: The skill provides examples for using the belt CLI tool via Bash. These commands are limited to interacting with the inference.sh platform's API for media generation and merging. The YAML frontmatter correctly restricts tool access to the belt command only (allowed-tools: Bash(belt *)).
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a workflow that ingests image files and text prompts. While this represents an ingestion surface for untrusted data, the skill is a static guide, and the examples use well-structured JSON payloads that separate code/logic from data inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:20 PM
Security Audit — agent-trust-hub — image-to-video