video-analyzer
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill implements secure command execution by using list-based arguments with
subprocess.runinscripts/extract.py. This approach prevents shell injection vulnerabilities by ensuring that user-provided paths are treated as literal arguments rather than executable shell code. The skill also defines a command structure inSKILL.mdfor executing its extraction script with user-provided video paths. - [EXTERNAL_DOWNLOADS]: The documentation references
ffmpeg.orgfor the necessaryffmpegutility. As this is a well-known and trusted source for video processing software, it does not pose a security risk to the user or the agent environment. - [DATA_EXPOSURE]: The skill reads from user-specified video paths and writes output (extracted frames and a manifest) to a local
video-analyzerdirectory relative to the video file. It does not attempt to access sensitive system files (e.g., SSH keys, credentials) or perform unauthorized network operations. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted video files provided by the user.
- Ingestion points: The
scripts/extract.pyscript accepts a user-provided video file path as its primary input for frame extraction. - Boundary markers: Not explicitly defined in the video processing stage; however, the agent's workflow relies on the model's visual reasoning capabilities for analysis based on specific user descriptions.
- Capability inventory: The skill uses
subprocess.runto callffmpegandffprobe, and utilizespathlibfor local file and directory management. No network capabilities or arbitrary code execution paths are available. - Sanitization: Input paths are validated for existence in the Python script, and shell execution is avoided during command invocation. This processing surface is inherent to the skill's purpose and is managed safely.
Audit Metadata