creative-production-positioning-explorer

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes a local batch runner script (plugins/creative-production/runtime/codex_exec_image_batch.py) to manage image generation jobs. This script interacts with platform-native tools and is part of the vendor's intended functionality.
  • [PROMPT_INJECTION]: The skill processes user-provided 'business briefs' and 'feedback' to generate positioning routes and image prompts, creating an indirect prompt injection surface.
  • Ingestion points: User briefs, growth bets, and language feedback in SKILL.md and experience-contract.md.
  • Boundary markers: No specific delimiters or safety instructions are explicitly defined for these inputs in the prompt construction logic.
  • Capability inventory: The skill can execute shell commands and write to local output directories via its batch runner and renderer scripts.
  • Sanitization: No explicit sanitization or validation of the ingested user content is documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 06:05 PM
Security Audit — agent-trust-hub — creative-production-positioning-explorer