byted-mediakit

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill transmits media data to Volcengine's official API endpoints at 'vod.volcengineapi.com'. Access to the local file system is governed by a robust path validation mechanism in 'scripts/upload_media.py', which restricts operations to authorized directories such as 'workspace/', 'userdata/', and '/tmp'.\n- [COMMAND_EXECUTION]: The skill operates by executing internal Python scripts to orchestrate media processing workflows. These operations are consistent with the skill's stated purpose and utilize secure cloud APIs for processing.\n- [SAFE]: The skill includes specific guardrail instructions for the AI agent (e.g., in 'references/26-drama-script.md') advising against downloading or directly parsing generated output files. This serves as a proactive mitigation against potential indirect prompt injection or resource exhaustion from processed content.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 08:42 AM