editor-post-production

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use FFmpeg for video concatenation, loudnorm volume normalization, audio mixing, and resizing. These commands are standard for media processing and include typical parameters for professional output.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with legitimate service endpoints at vidjutsu.ai (for overlays and uploads) and api.kie.ai (for music generation). These interactions are required for the skill's stated purpose and follow standard API integration patterns.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: Uses environment variables for API key management (VIDJUTSU_API_KEY), which is a recommended security practice for handling sensitive credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data, presenting a minor surface for indirect injection. 1. Ingestion points: The skill accepts data through the overlayText and music prompt fields. 2. Boundary markers: Absent; no specific delimiters are defined to isolate these inputs from the system instructions. 3. Capability inventory: The skill has the ability to execute shell commands via FFmpeg and perform network requests to external APIs. 4. Sanitization: Absent; no specific validation or sanitization instructions are provided for user-supplied strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 01:53 AM
Security Audit — agent-trust-hub — editor-post-production