google-veo
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
infshcommand-line tool to run video generation models and manage application sessions. This tool is explicitly listed in theallowed-toolsmetadata, which restricts the agent's shell capabilities to the vendor's specific utility. - [EXTERNAL_DOWNLOADS]: The documentation provides a link to a CLI installation guide hosted on the vendor's GitHub repository (
github.com/inference-sh/skills). This is a standard setup process for the provided inference service. - [REMOTE_CODE_EXECUTION]: The skill suggests using the
npx skills addcommand to incorporate related functionality from the vendor's ecosystem. This command facilitates the download and execution of additional skill modules from theinference-shGitHub organization.
Audit Metadata