video-subtitle-remover
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill executes code directly from a network source by piping the output of a
curlcommand into a Python interpreter. This allows an external repository to run arbitrary commands on the host system. - [EXTERNAL_DOWNLOADS]: The skill fetches numerous files, including scripts and binary models, from an untrusted GitHub repository (
YaoFANGUK/video-subtitle-remover). These downloads are not from a verified or well-known service. - [COMMAND_EXECUTION]: The skill executes multiple shell commands to install packages, download files, and run processing scripts on the local system.
- [DYNAMIC_EXECUTION]: The skill involves the runtime creation of a startup script (
run_remove.py) and the modification of existing code files (backend/config.py) using agent tools. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted video files via OCR, creating an injection surface. 1. Ingestion points: user-provided video files (SKILL.md). 2. Boundary markers: none specified (SKILL.md). 3. Capability inventory: subprocess calls, file-write, and network operations (SKILL.md). 4. Sanitization: no evidence of output filtering or sanitization (SKILL.md).
Recommendations
- HIGH: Downloads and executes remote code from: https://api.github.com/repos/YaoFANGUK/video-subtitle-remover/git/trees/main?recursive=1 - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata