byted-mediakit-editing

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation guides the user to install the @volcengine/mediakit-cli package from the official NPM registry. As this is a vendor-provided tool from Volcano Engine, this is considered a standard and safe dependency installation for the skill's intended use.
  • [COMMAND_EXECUTION]: The skill leverages the shell permission to execute mediakit-cli commands. These commands are used to perform media editing operations such as cropping, speed adjustment, and filtering. The command structures are well-defined and scoped to the editing domain of the tool.
  • [CREDENTIALS_UNSAFE]: The skill mentions the use of MEDIAKIT_API_KEY for cloud-based media processing. It correctly advises storing these credentials in environment variables or a local configuration file (~/.mediakit/config.json) rather than hardcoding them within the skill instructions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external media resources via URLs (e.g., video_url, audio_url). While these are ingestion points for external data, the skill acts as a wrapper for a specialized media processing CLI, and there is no evidence of these inputs being unsafely interpolated into system prompts or used for dynamic code generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 12:05 PM
Security Audit — agent-trust-hub — byted-mediakit-editing