video-craft
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
SKILL.mdfile contains bash scripts in 'Preamble' and 'Telemetry' sections that perform local file operations and network requests for usage tracking. - [COMMAND_EXECUTION]: Scripts read and write to
~/.superstack/to manage configuration and session logs, including checking for user consent before activity logging. - [COMMAND_EXECUTION]: A
curlcommand transmits anonymized metadata (version, platform info, and event status) to a telemetry endpoint defined in the local configuration file. - [SAFE]: The skill guidelines for screenshots explicitly mandate the removal of personal data and the use of realistic fake data, demonstrating good security and privacy practices.
Audit Metadata