avatar-video
Pass
Audited by Gen Agent Trust Hub on Mar 14, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides curl command examples for developers to interact with HeyGen API endpoints for listing resources, uploading assets, and initiating video generation.
- [DATA_EXFILTRATION]: The skill facilitates the reading of local media files (images, audio, and video) for the purpose of uploading them to the HeyGen platform as video assets, which is a documented core feature.
- [EXTERNAL_DOWNLOADS]: Logic is provided to fetch media assets from user-supplied HTTPS URLs to be re-uploaded to HeyGen's infrastructure for processing.
- [PROMPT_INJECTION]: The skill documentation includes examples of processing user-provided text as scripts for AI avatars to speak, which is the primary intended function of the HeyGen service.
Audit Metadata