media-use
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads media assets and models from established sources including the author's own domain (heygen.ai), Google Cloud (googleapis.com), and HuggingFace. A dedicated helper (
media-fetch.mjs) implements host validation against a blocklist of internal and private IP ranges to prevent SSRF (Server-Side Request Forgery). - [COMMAND_EXECUTION]: The skill extensively uses
spawnSyncandexecFileSyncto coordinate external tools such as FFmpeg, ffprobe, and Python. These calls are implemented securely by passing arguments as arrays rather than through a shell, mitigating the risk of command injection from user-supplied metadata or project paths. - [DYNAMIC_EXECUTION]: Audio generation logic in
bgm.mjsdynamically constructs and executes Python scripts to interface with MusicGen. This implementation uses proper JSON serialization for parameters, ensuring that user-provided prompts cannot break out of the script's string literals. - [CREDENTIALS_UNSAFE]: While the skill manages sensitive API keys for services like Gemini and ElevenLabs, it follows safe practices by instructing users to utilize environment variables or secure credential files. Additionally, the Gemini authentication helpers explicitly redact secrets and raw library exceptions from their output to prevent accidental exposure in logs.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests structured data from project files (HTML compositions and JSON requests). It manages the risk of malicious content in these files by using strict JSON parsing and targeted regex for attribute extraction, maintaining a low attack surface for this category.
Audit Metadata