video-assemble

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill executes external tools like ffmpeg and ffprobe using subprocess.run with argument lists rather than shell strings, effectively preventing command injection vulnerabilities.\n- [SAFE]: Security-conscious file handling is implemented in scripts/jianying_writer.py, which includes explicit checks against path traversal during ZIP extraction and file bundling.\n- [SAFE]: Configuration and API management in scripts/lib.py rely on environment variables for sensitive data like MIMO_API_KEY, avoiding hardcoded credentials.\n- [SAFE]: The skill uses localized processing for its operations, and all internal logic for audio mixing, subtitle generation, and metadata handling is transparent and consistent with its stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 06:21 PM
Security Audit — agent-trust-hub — video-assemble