ingest-video
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests video content from external, user-provided URLs and later processes the resulting transcript. This transcript data is untrusted and could contain malicious instructions designed to manipulate the agent during the summarization step.
- Ingestion points: External data processed via
get_transcriptas described inSKILL.md. - Boundary markers: None identified in the instructions to separate untrusted transcript text from agent instructions.
- Capability inventory: The skill uses
upload_video,get_upload_status,get_project,get_transcripttools, and executes shell commands (sleep) via Bash. - Sanitization: No validation or sanitization of the transcript content is specified before the agent is asked to summarize it.
- [COMMAND_EXECUTION]: The instructions explicitly direct the agent to execute shell commands (
sleep 30via Bash) to manage polling intervals during the upload process. - [EXTERNAL_DOWNLOADS]: The skill is designed to initiate downloads from external sources, including Google Drive and other public URLs, by passing these addresses to backend ingestion tools.
Audit Metadata