byted-mediakit-editing
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation guides the user to install the
@volcengine/mediakit-clipackage from the official NPM registry. As this is a vendor-provided tool from Volcano Engine, this is considered a standard and safe dependency installation for the skill's intended use. - [COMMAND_EXECUTION]: The skill leverages the
shellpermission to executemediakit-clicommands. These commands are used to perform media editing operations such as cropping, speed adjustment, and filtering. The command structures are well-defined and scoped to theeditingdomain of the tool. - [CREDENTIALS_UNSAFE]: The skill mentions the use of
MEDIAKIT_API_KEYfor cloud-based media processing. It correctly advises storing these credentials in environment variables or a local configuration file (~/.mediakit/config.json) rather than hardcoding them within the skill instructions. - [INDIRECT_PROMPT_INJECTION]: The skill processes external media resources via URLs (e.g.,
video_url,audio_url). While these are ingestion points for external data, the skill acts as a wrapper for a specialized media processing CLI, and there is no evidence of these inputs being unsafely interpolated into system prompts or used for dynamic code generation.
Audit Metadata