byted-airesearch-videoeval

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill uploads video files to Volcano Engine's official console domain (console.volcengine.com). This network activity is directed to the author's own infrastructure and is necessary for the skill's primary function of material evaluation.
  • [CREDENTIALS_UNSAFE]: The skill uses API keys for authentication, which are retrieved from environment variables or command-line arguments. No sensitive keys or tokens are hardcoded within the scripts.
  • [COMMAND_EXECUTION]: Python scripts are employed to handle API orchestration and file validation. Analysis of the source code found no instances of unsafe command execution or user-controlled input being passed to shell-executing functions.
  • [PROMPT_INJECTION]: The instructional content in SKILL.md defines specific workflows and constraints for the agent. It does not contain patterns intended to bypass safety filters, extract system prompts, or override agent behavior maliciously.
  • [EXTERNAL_DOWNLOADS]: The skill uses the standard 'requests' library for network operations. It does not perform any remote code execution or download scripts from untrusted external repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 07:25 AM