skills/t0ugh/videoclaw/video-i2v/Gen Agent Trust Hub

video-i2v

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes uvx to execute the videoclaw package from the Python Package Index (PyPI). This is a standard and legitimate method for running Python-based utilities without permanent installation.- [COMMAND_EXECUTION]: The skill facilitates the execution of the videoclaw CLI tool. It passes user-provided arguments such as project names, image paths, and text prompts directly to the CLI, which is consistent with its intended purpose.- [PROMPT_INJECTION]: There is a surface for indirect prompt injection as user-supplied text for the --prompt argument is interpolated into a command. However, the risk is minimal as the input is passed as an argument to a specialized video generation tool and not used to override agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 08:40 AM
Security Audit — agent-trust-hub — video-i2v