video-assemble
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill executes external tools like
ffmpegandffprobeusingsubprocess.runwith argument lists rather than shell strings, effectively preventing command injection vulnerabilities.\n- [SAFE]: Security-conscious file handling is implemented inscripts/jianying_writer.py, which includes explicit checks against path traversal during ZIP extraction and file bundling.\n- [SAFE]: Configuration and API management inscripts/lib.pyrely on environment variables for sensitive data likeMIMO_API_KEY, avoiding hardcoded credentials.\n- [SAFE]: The skill uses localized processing for its operations, and all internal logic for audio mixing, subtitle generation, and metadata handling is transparent and consistent with its stated purpose.
Audit Metadata