audio-extract

Pass

Audited by Gen Agent Trust Hub on Mar 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the agent-media CLI tool to perform audio extraction via a bundled ffmpeg binary.
  • [PROMPT_INJECTION]: The skill documentation describes a surface for indirect prompt injection by accepting user-provided paths and URLs.
  • Ingestion points: The --in parameter in SKILL.md accepts external file paths and URLs for processing.
  • Boundary markers: No boundary markers or 'ignore' instructions are present to delimit the external content.
  • Capability inventory: The skill triggers subprocess execution through the agent-media command.
  • Sanitization: No input validation or sanitization of the provided file paths or URLs is specified in the documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 5, 2026, 12:37 AM