tavus-video-gen

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [Prompt Injection] (SAFE): No instructions found that attempt to bypass safety filters or override agent instructions.
  • [Data Exposure & Exfiltration] (SAFE): No hardcoded secrets or access to sensitive local files detected. Network operations target the legitimate service domain tavusapi.com.
  • [Indirect Prompt Injection] (LOW): The skill defines an attack surface for untrusted data ingestion. 1. Ingestion points: Parameters like script, audio_url, and callback_url in SKILL.md. 2. Boundary markers: Absent in examples. 3. Capability inventory: Network requests via curl. 4. Sanitization: Not specified in documentation.
  • [Remote Code Execution] (SAFE): No remote scripts or dynamic code execution patterns identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 04:37 PM