byted-mediakit-video

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the shell permission to execute the mediakit-cli tool. This is consistent with its stated purpose of providing a command-line interface for video processing services.
  • [EXTERNAL_DOWNLOADS]: The documentation in reference/shared.md instructs users to install the @volcengine/mediakit-cli package from the official npm registry. This is a standard installation procedure for a vendor-provided tool and does not present a security risk.
  • [CREDENTIALS_UNSAFE]: The skill describes the use of MEDIAKIT_API_KEY for authentication. It correctly advises users to manage these credentials via environment variables or a local configuration file (~/.mediakit/config.json) rather than hardcoding them in the skill itself.
  • [SAFE]: No evidence of prompt injection, data exfiltration, obfuscation, or persistence mechanisms was found in the analyzed files. The instructions are clear, professional, and limited to the scope of video processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 05:47 AM
Security Audit — agent-trust-hub — byted-mediakit-video