skills/skillssh/skills/google-veo/Gen Agent Trust Hub

google-veo

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides installation guidance for the infsh CLI tool via a link to a GitHub repository (inference-sh/skills) and suggests adding related skills using npx. These resources are managed by the service provider and are standard for tool integration.\n- [COMMAND_EXECUTION]: Core functionality is implemented through the execution of the infsh command-line tool via the shell.\n- [PROMPT_INJECTION]: The skill processes user-supplied text to generate video prompts. This creates an indirect prompt injection surface, which is inherent to the intended use case of video generation.\n
  • Ingestion points: Prompt content passed to the infsh app run command via the --input JSON payload.\n
  • Boundary markers: No specific delimiters or boundary markers are defined in the provided instruction examples.\n
  • Capability inventory: Shell command execution using the infsh CLI.\n
  • Sanitization: No explicit sanitization or input validation mechanisms are described within the skill's instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 07:31 PM