talking-head-production

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the infsh command-line interface to execute media generation tasks, including text-to-speech, portrait generation, and video synthesis.
  • [EXTERNAL_DOWNLOADS]: References installation instructions and additional functionality from the vendor's official GitHub repositories and package registries.
  • [REMOTE_CODE_EXECUTION]: Utilizes npx to install and add related skills directly from the vendor's repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-defined text prompts to generate audio and video content.
  • Ingestion points: The prompt field within the JSON input of infsh app run commands in SKILL.md.
  • Boundary markers: Not present; the prompts are passed directly to the tool.
  • Capability inventory: Shell command execution via the infsh tool.
  • Sanitization: No explicit sanitization or validation of the input strings is performed within the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 12:27 PM