embedded-captions

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads model weights for background removal (u2net_human_seg, ~168 MB) via the platform CLI and uses the uvx runner to fetch the whisperx Python package for transcription tasks.
  • [REMOTE_CODE_EXECUTION]: In transcribe.cjs, the skill executes the whisperx utility directly using uvx with a pinned version (3.8.6). This is a functional requirement for high-accuracy word-level alignment in the captioning pipeline.
  • [COMMAND_EXECUTION]: The skill relies on system utilities including ffmpeg and ffprobe for audio/video manipulation, and uses puppeteer to measure rendered HTML layout for pixel-perfect occlusion logic.
  • [DYNAMIC_EXECUTION]: The rendering pipeline generates a shell script (_postfx.sh) at runtime to apply complex ffmpeg filters for final visual effects (e.g., film grain, lens jitter) and executes it to produce the final video.
  • [SAFE]: Analysis of the 97 files confirms that all detected behaviors, including dependency installation and command execution, are consistent with the skill's stated purpose. No malicious patterns, prompt injections, or unauthorized data access attempts were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 05:02 PM
Security Audit — agent-trust-hub — embedded-captions