ai-avatar-video

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified. The skill's behavior is consistent with its stated purpose of providing an interface to the inference.sh service.\n- [COMMAND_EXECUTION]: The skill uses the 'belt' CLI tool to interact with AI models. The use of the tool is restricted via the 'allowed-tools' configuration in the frontmatter, ensuring the agent only executes intended commands.\n- [EXTERNAL_DOWNLOADS]: The skill references the official installation script for the 'belt' CLI and provides instructions to add the 'belt-sh/cli' package. These resources originate from the service provider's infrastructure and are necessary for the skill's operation.\n- [PROMPT_INJECTION]: The skill ingests user-defined text for voice scripts and prompts. While this represents a surface for potential indirect prompt injection where instructions could be embedded in processed data, it is an inherent part of the AI media generation workflow and does not conflict with the agent's core instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 09:04 AM
Security Audit — agent-trust-hub — ai-avatar-video