yyl-benchmark-breakdown

Warn

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill pulls third-party Docker images (evil0ctal/douyin_tiktok_download_api and joeanamier/xhs-downloader) and downloads content from various social media platforms to facilitate local analysis.
  • [COMMAND_EXECUTION]: Executes several shell scripts (check-deps.sh, prepare-assets.sh, bootstrap-local-apis.sh) that interact with the local filesystem and system binaries including ffmpeg, ffprobe, docker, and whisper.
  • [REMOTE_CODE_EXECUTION]: The workflow depends on external logic running within Docker containers and third-party scraping APIs (tikhub.io, jina.ai) to extract metadata and media from remote URLs, effectively executing third-party provided code/logic as part of the teardown process.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 5, 2026, 02:22 PM
Security Audit — agent-trust-hub — yyl-benchmark-breakdown