byted-mediakit-video
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill requires shell permissions to execute the
mediakit-clibinary for processing video data. - [EXTERNAL_DOWNLOADS]: The documentation instructs the user to install the
@volcengine/mediakit-clipackage from the npm registry. This is a vendor-provided dependency from volcengine required for the skill to function. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of untrusted external media files to extract text (OCR, ASR), which creates an attack surface for indirect prompt injection.
- Ingestion points: Processes external video and audio files via
video_urlandaudio_urlparameters in tools such asvideo-ocr,asr-subtitles, andanalyze-video-highlights(SKILL.md, reference/video-ocr.md). - Boundary markers: There are no explicit instructions or delimiters mentioned to separate extracted text from the agent's internal reasoning or system instructions.
- Capability inventory: The skill possesses the
shellpermission to execute system commands through the CLI tool. - Sanitization: The skill does not describe any mechanisms for filtering, escaping, or sanitizing the text extracted from videos before it is incorporated into the agent's context.
Audit Metadata