creative-pipeline

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous templates and functions for executing ffmpeg commands via the allowed Bash tool to automate video assembly and social media export.
  • Evidence: Found in SKILL.md and references/ffmpeg-presets.sh wrapping common video processing tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as an intermediary that processes engineering data from dependencies like blueprint-engine to generate executable Python and Shell code, creating a functional attack surface for untrusted data.
  • Ingestion points: DIMENSIONS and LAYOUT data from blueprint-engine used to scale meshes and route pipes in SKILL.md.
  • Boundary markers: Absent; the skill directly interpolates design data into script templates.
  • Capability inventory: The skill is designed to generate bpy scripts (Python) and ffmpeg commands (Bash).
  • Sanitization: No explicit validation or escaping of the design data is performed before it is injected into the generated code snippets.
  • [EXTERNAL_DOWNLOADS]: The documentation references Polyhaven for obtaining high-quality HDRI environment maps for realistic lighting.
  • Evidence: SKILL.md suggests downloading industrial HDRI files from polyhaven.com.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 01:15 PM
Security Audit — agent-trust-hub — creative-pipeline