bailian-gen
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute the
blCLI tool for interacting with Aliyun Bailian services. It also suggests usingffmpegfor local video post-processing tasks like concatenation and audio muxing. - [INDIRECT_PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection as it processes untrusted user data (images, videos, and audio) through multimodal models (
bl vision,bl omni). - Ingestion points:
bl image edit,bl video edit,bl omni,bl vision describe, andbl speech recognizeaccept user-provided file paths or URLs. - Capability inventory: The skill has the capability to write to the local file system (
--out,--download) and execute shell commands (bl). - Boundary markers: None explicitly mentioned for model inputs.
- Sanitization: Not specified for model outputs before they are processed by the agent.
- [DATA_HANDLING]: The
blCLI automatically handles the upload of local files to DashScope temporary storage (OSS) for processing. This is a standard functional requirement for the service and is clearly documented.
Audit Metadata