byted-mediakit-audio

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation provides instructions to install the @volcengine/mediakit-cli package from the public NPM registry. This is an official dependency related to the vendor.
  • [COMMAND_EXECUTION]: The skill defines tools that execute the mediakit-cli binary via shell commands. This is consistent with the skill's purpose and declared permissions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources via audio_url and video_url parameters.
  • Ingestion points: audio_url and video_url parameters in the separate-voice and probe-audio-metadata tools.
  • Boundary markers: No explicit boundary markers or safety warnings for the LLM regarding embedded content in media files are defined in the instructions.
  • Capability inventory: Shell execution of the mediakit-cli tool.
  • Sanitization: The skill relies on the underlying CLI tool to handle and sanitize the content retrieved from external URLs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 12:44 PM
Security Audit — agent-trust-hub — byted-mediakit-audio