minimax-multimodal-toolkit
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses environment variables for sensitive data like API keys (
MINIMAX_API_KEY), following standard security practices for secret management. - [SAFE]: All network operations are directed to official MiniMax API endpoints (
api.minimaxi.comandapi.minimax.io). No unauthorized external domains were detected. - [SAFE]: The scripts use
jqwith the--argflag to construct JSON payloads, which effectively prevents injection attacks by ensuring data is treated as strings rather than executable code. - [SAFE]: Subprocess calls are restricted to well-known, legitimate media processing and utility tools including
ffmpeg,ffprobe,curl,jq, andxxd. - [SAFE]: The skill implements a robust environment check (
scripts/check_environment.sh) to verify prerequisites and connectivity before execution. - [SAFE]: Local file handling is performed using provided paths with no evidence of directory traversal or unauthorized access to sensitive system files.
- [SAFE]: The instructions in
SKILL.mdare purely operational and do not contain any patterns indicative of prompt injection or attempts to override agent safety protocols.
Audit Metadata