together-video
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes Python and TypeScript scripts that interact with the local file system to save generated videos and make network requests to official API endpoints. These actions are necessary for the skill's primary function and do not appear to be malicious.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied text prompts and image URLs. While this presents a standard attack surface for indirect prompt injection, the skill relies on the Together AI platform's internal safety controls for content generation.
- [EXTERNAL_DOWNLOADS]: The scripts facilitate downloading media files from Together AI's infrastructure once generation jobs are complete. The domains used are legitimate vendor resources.
Audit Metadata