creative-production-positioning-explorer
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes a local batch runner script (plugins/creative-production/runtime/codex_exec_image_batch.py) to manage image generation jobs. This script interacts with platform-native tools and is part of the vendor's intended functionality.
- [PROMPT_INJECTION]: The skill processes user-provided 'business briefs' and 'feedback' to generate positioning routes and image prompts, creating an indirect prompt injection surface.
- Ingestion points: User briefs, growth bets, and language feedback in SKILL.md and experience-contract.md.
- Boundary markers: No specific delimiters or safety instructions are explicitly defined for these inputs in the prompt construction logic.
- Capability inventory: The skill can execute shell commands and write to local output directories via its batch runner and renderer scripts.
- Sanitization: No explicit sanitization or validation of the ingested user content is documented.
Audit Metadata