talking-head-production
Pass
Audited by Gen Agent Trust Hub on Apr 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Mentions documentation and installation guides for the
infshCLI tool from the vendor's official GitHub repository. - [COMMAND_EXECUTION]: Utilizes the
infshcommand-line tool for authentication and running production apps. The tool is properly scoped in the skill configuration metadata. - [REMOTE_CODE_EXECUTION]: Triggers AI model inference on the vendor's remote infrastructure for tasks including text-to-speech and video generation.
- [PROMPT_INJECTION]: The skill processes user-supplied text for media generation, creating an indirect prompt injection surface. Ingestion points: Prompts for TTS and image generation in SKILL.md. Boundary markers: Absent. Capability inventory: infsh tool. Sanitization: Absent. This is characteristic of media generation skills and is considered safe within the intended usage context.
Audit Metadata