ingest-video

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests video content from external, user-provided URLs and later processes the resulting transcript. This transcript data is untrusted and could contain malicious instructions designed to manipulate the agent during the summarization step.
  • Ingestion points: External data processed via get_transcript as described in SKILL.md.
  • Boundary markers: None identified in the instructions to separate untrusted transcript text from agent instructions.
  • Capability inventory: The skill uses upload_video, get_upload_status, get_project, get_transcript tools, and executes shell commands (sleep) via Bash.
  • Sanitization: No validation or sanitization of the transcript content is specified before the agent is asked to summarize it.
  • [COMMAND_EXECUTION]: The instructions explicitly direct the agent to execute shell commands (sleep 30 via Bash) to manage polling intervals during the upload process.
  • [EXTERNAL_DOWNLOADS]: The skill is designed to initiate downloads from external sources, including Google Drive and other public URLs, by passing these addresses to backend ingestion tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 07:41 PM
Security Audit — agent-trust-hub — ingest-video