videocut-clip
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill orchestrates the execution of local command-line tools by generating a complex filter script (
filter.txt) and runningffmpegto process video files. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface where it ingests and processes external task lists that could contain malicious data or structure.
- Ingestion points: Ingests user-supplied deletion tasks and transcription data as detailed in
SKILL.md. - Boundary markers: Absent; there are no explicit data encapsulation boundaries or structural schemas defined for separating untrusted user data from agent logic.
- Capability inventory: Incorporates command execution capabilities via local shell invocation of
ffmpegdescribed inSKILL.md. - Sanitization: Partially addressed via instructions that mandate parsing explicit timestamps
(start-end)directly rather than executing text searches, which minimizes simple text-based prompt manipulation but lacks rigorous validation.
Audit Metadata