skills/vesely/skills/screencast/Gen Agent Trust Hub

screencast

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes external binaries such as ffmpeg, ffprobe, and agent-browser to record and render video content. It also runs npm to install necessary Node.js dependencies in the skill's directory.
  • [EXTERNAL_DOWNLOADS]: The skill downloads the @napi-rs/canvas package from the NPM registry during its initial rendering task if the dependency is not already present. This is a documented self-installation step.
  • [SAFE]: Security best practices are followed for data handling, including the automatic redaction of password input fields and the inclusion of a --private flag to prevent sensitive strings from appearing in event logs or video overlays. Furthermore, it explicitly sets restrictive filesystem permissions (0o700 for directories and 0o600 for files) to protect session data from unauthorized local access.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 08:22 AM
Security Audit — agent-trust-hub — screencast