skills/theorcdev/skills/intro-video/Gen Agent Trust Hub

intro-video

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads an ASR model (sherpa-onnx-zipformer) from a well-known repository (github.com/k2-fsa/sherpa-onnx/releases). This is a standard functional dependency for speech-to-text features.\n- [COMMAND_EXECUTION]: The asr.py script uses subprocess.run to invoke ffmpeg for audio conversion and silences detection. The command arguments are constructed safely from specific flags and path strings, posing no command injection risk under normal use.\n- [SAFE]: The skill includes instructions for rendering video chunks to manage resource limits and uses standard open-source tools (npm, PyPI) for dependencies. No indicators of data exfiltration, obfuscation, or persistence were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 02:29 PM
Security Audit — agent-trust-hub — intro-video