video-subtitle-remover

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill executes code directly from a network source by piping the output of a curl command into a Python interpreter. This allows an external repository to run arbitrary commands on the host system.
  • [EXTERNAL_DOWNLOADS]: The skill fetches numerous files, including scripts and binary models, from an untrusted GitHub repository (YaoFANGUK/video-subtitle-remover). These downloads are not from a verified or well-known service.
  • [COMMAND_EXECUTION]: The skill executes multiple shell commands to install packages, download files, and run processing scripts on the local system.
  • [DYNAMIC_EXECUTION]: The skill involves the runtime creation of a startup script (run_remove.py) and the modification of existing code files (backend/config.py) using agent tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted video files via OCR, creating an injection surface. 1. Ingestion points: user-provided video files (SKILL.md). 2. Boundary markers: none specified (SKILL.md). 3. Capability inventory: subprocess calls, file-write, and network operations (SKILL.md). 4. Sanitization: no evidence of output filtering or sanitization (SKILL.md).
Recommendations
  • HIGH: Downloads and executes remote code from: https://api.github.com/repos/YaoFANGUK/video-subtitle-remover/git/trees/main?recursive=1 - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 06:24 AM
Security Audit — agent-trust-hub — video-subtitle-remover