capcut-video-editor
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external media files (mp4, mov, etc.) and user messages which are sent to the NemoVideo API. This presents an indirect prompt injection surface where adversarial content in the data could potentially influence the agent's instructions.
- Ingestion points: User video uploads and descriptive prompts as described in SKILL.md.
- Boundary markers: The skill does not define specific delimiters or instructions to ignore potential commands within the uploaded video data or metadata.
- Capability inventory: The skill performs network operations to the NemoVideo API (mega-api-prod.nemovideo.ai) to process tasks, manage sessions, and query project state.
- Sanitization: There is no evidence of sanitization, validation, or filtering of content extracted from processed media files before it is processed by the AI pipeline.
Audit Metadata