csv-quiz-video
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The orchestrator script
build_video.pyinvokesmanimandffmpegusingsubprocess.runwith list-formatted arguments. This prevents shell injection by ensuring that user-provided inputs, such as video titles or CSV file paths, are treated as literal arguments rather than executable shell code. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from user-provided CSV files to generate video content and narration. While the execution flow is secure, the content itself is not sanitized as it is intended for literal rendering.
- Ingestion points:
parse_csv.pyreads question and explanation text from the CSV input. - Boundary markers: No explicit delimiters are used to isolate CSV text from the agent's context during processing.
- Capability inventory: File system access, network requests to Sarvam AI, and shell command execution.
- Sanitization: Content is not sanitized; however, the impact is minimized by the skill's primary focus on media generation. A risk factor exists if the AI agent interprets instructions embedded in the CSV content as valid commands during the review phase.
- [DYNAMIC_EXECUTION]: The skill uses Manim to render animations based on a JSON configuration file loaded at runtime by
quiz_scene.py. This configuration is passed securely via an environment variable to a child Python process. This is a standard and necessary pattern for the Manim engine and is implemented without exposing the system to external code injection. - [DATA_EXFILTRATION]: The skill transmits text content to
api.sarvam.aifor TTS synthesis. This is a documented functional requirement using a well-known service. TheSARVAM_API_KEYis securely fetched from the environment or a local.envfile, adhering to secret management best practices.
Audit Metadata