media-processing

Warn

Audited by Gen Agent Trust Hub on Feb 20, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • Privilege Escalation (MEDIUM): The skill documentation contains commands using sudo for administrative tasks such as software installation and editing system-level security policies (/etc/ImageMagick-7/policy.xml). Executing these commands could allow an agent to gain unauthorized administrative access or weaken system security.\n- Unverifiable Dependencies & Remote Code Execution (LOW): Recommends downloading binaries from external official sources. While reputable, these remain external dependencies.\n- Indirect Prompt Injection (LOW): The skill's ingestion of external media files presents an indirect prompt injection surface.\n
  • Ingestion points: ffmpeg -i and magick input arguments.\n
  • Boundary markers: Absent in command templates.\n
  • Capability inventory: Subprocess execution of powerful media manipulation tools including networking capabilities (RTMP/HLS).\n
  • Sanitization: None described.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 20, 2026, 01:10 AM