csv-landscape-video-pipeline
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied CSV files where content is interpolated into generated Python scripts and TTS narration scripts, creating a surface for indirect prompt injection.
- Ingestion points: The
scripts/parse_csv.pyscript reads external CSV data from theinput/directory. - Boundary markers: No explicit delimiters or instructions are used to prevent the LLM or subsequent processing steps from interpreting data as instructions.
- Capability inventory: The skill has the ability to execute shell commands (
ffmpeg,manim), generate and run Python scripts, and perform network operations. - Sanitization: Basic whitespace cleaning and rudimentary LaTeX escaping are applied, but these do not fully sanitize against logical injection in the code generation phase.
- [DYNAMIC_EXECUTION]: The skill uses a code generation pattern where it dynamically creates a Manim animation script (
script.py) containing data from the CSV, which is then executed by the system. - Evidence:
scripts/generate_scenes.pybuilds thescript.pyfile using string concatenation and interpolation of CSV-derived data. - [COMMAND_EXECUTION]: The skill executes shell commands with
shell=True, which is a recognized security risk if command arguments are not strictly controlled. - Evidence:
scripts/add_audio.pyusessubprocess.run(cmd, shell=True, ...)to invokeffmpegandedge-tts. While most arguments are derived from configuration, the pattern is susceptible to command injection if configuration values or filenames are manipulated. - [EXTERNAL_DOWNLOADS]: The skill interacts with external API services and CLI tools to generate media content.
- Evidence:
scripts/add_audio.pymakes network requests toapi.sarvam.aifor premium TTS and utilizes theedge-ttspackage for fallback audio generation.
Audit Metadata