talking-head-production
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the infsh command-line interface to execute media generation tasks, including text-to-speech, portrait generation, and video synthesis.
- [EXTERNAL_DOWNLOADS]: References installation instructions and additional functionality from the vendor's official GitHub repositories and package registries.
- [REMOTE_CODE_EXECUTION]: Utilizes npx to install and add related skills directly from the vendor's repository.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-defined text prompts to generate audio and video content.
- Ingestion points: The prompt field within the JSON input of infsh app run commands in SKILL.md.
- Boundary markers: Not present; the prompts are passed directly to the tool.
- Capability inventory: Shell command execution via the infsh tool.
- Sanitization: No explicit sanitization or validation of the input strings is performed within the skill instructions.
Audit Metadata