videocut-install
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands to install necessary dependencies. This includes using
pipfor Python packages andbreworaptfor system-level tools like FFmpeg. - [EXTERNAL_DOWNLOADS]: The installation process involves downloading third-party Python libraries (
funasr,modelscope,openai-whisper) from PyPI and large pre-trained models (approximately 5GB) from well-known AI model hosting services (ModelScope and OpenAI). - [PRIVILEGE_ESCALATION]: The skill includes a command to install FFmpeg on Linux using
sudo apt install. This requires elevated privileges but is a standard procedure for system package installation during environment setup. - [INDIRECT_PROMPT_INJECTION]: The environment verification step (Step 5) involves processing a media file (
test.mp4) using an automated speech recognition model. This represents a potential entry point for untrusted data into the agent's context. - Ingestion points: The
model.generate(input="test.mp4")call inSKILL.mdreads content from a file to verify the installation. - Boundary markers: None are present in the verification script.
- Capability inventory: The skill has the capability to execute shell commands (
pip,apt,brew) as defined inSKILL.md. - Sanitization: The output of the model transcription is printed directly to the console without sanitization.
Audit Metadata