video-analyzer

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill implements secure command execution by using list-based arguments with subprocess.run in scripts/extract.py. This approach prevents shell injection vulnerabilities by ensuring that user-provided paths are treated as literal arguments rather than executable shell code. The skill also defines a command structure in SKILL.md for executing its extraction script with user-provided video paths.
  • [EXTERNAL_DOWNLOADS]: The documentation references ffmpeg.org for the necessary ffmpeg utility. As this is a well-known and trusted source for video processing software, it does not pose a security risk to the user or the agent environment.
  • [DATA_EXPOSURE]: The skill reads from user-specified video paths and writes output (extracted frames and a manifest) to a local video-analyzer directory relative to the video file. It does not attempt to access sensitive system files (e.g., SSH keys, credentials) or perform unauthorized network operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted video files provided by the user.
  • Ingestion points: The scripts/extract.py script accepts a user-provided video file path as its primary input for frame extraction.
  • Boundary markers: Not explicitly defined in the video processing stage; however, the agent's workflow relies on the model's visual reasoning capabilities for analysis based on specific user descriptions.
  • Capability inventory: The skill uses subprocess.run to call ffmpeg and ffprobe, and utilizes pathlib for local file and directory management. No network capabilities or arbitrary code execution paths are available.
  • Sanitization: Input paths are validated for existence in the Python script, and shell execution is avoided during command invocation. This processing surface is inherent to the skill's purpose and is managed safely.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:22 PM
Security Audit — agent-trust-hub — video-analyzer