Back to skill

Security audit

Ai Video Gen Pro

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only video generation skill that uses the inference.sh CLI, with expected third-party media handling users should understand before use.

Install only if you trust inference.sh and are comfortable logging into that service. Do not submit private, regulated, copyrighted, or non-consensual face or voice media unless you have approval and understand the provider's retention, privacy, and billing terms.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The examples encourage passing image, audio, and video URLs to third-party AI services without any notice about privacy, consent, retention, or sensitivity of uploaded media. In a video-generation skill, this is contextually more dangerous because users may submit personal portraits, voice recordings, or proprietary media, leading to unintended external disclosure or compliance issues.

Static analysis

No suspicious patterns detected.