videocut-install

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands to install necessary dependencies. This includes using pip for Python packages and brew or apt for system-level tools like FFmpeg.
  • [EXTERNAL_DOWNLOADS]: The installation process involves downloading third-party Python libraries (funasr, modelscope, openai-whisper) from PyPI and large pre-trained models (approximately 5GB) from well-known AI model hosting services (ModelScope and OpenAI).
  • [PRIVILEGE_ESCALATION]: The skill includes a command to install FFmpeg on Linux using sudo apt install. This requires elevated privileges but is a standard procedure for system package installation during environment setup.
  • [INDIRECT_PROMPT_INJECTION]: The environment verification step (Step 5) involves processing a media file (test.mp4) using an automated speech recognition model. This represents a potential entry point for untrusted data into the agent's context.
  • Ingestion points: The model.generate(input="test.mp4") call in SKILL.md reads content from a file to verify the installation.
  • Boundary markers: None are present in the verification script.
  • Capability inventory: The skill has the capability to execute shell commands (pip, apt, brew) as defined in SKILL.md.
  • Sanitization: The output of the model transcription is printed directly to the console without sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:24 AM
Security Audit — agent-trust-hub — videocut-install