video-script
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted external data sources including GitHub Pull Request descriptions, git logs, and local markdown files to generate script content.
- Ingestion points: Phase 1 (Discovery) reads content from PRs via the GitHub CLI, git history via
git diff/git log, and local files provided in arguments. - Boundary markers: The skill does not implement explicit delimiters or instructions to ignore embedded natural language commands when processing this external text.
- Capability inventory: The skill can read from the filesystem, interact with git/gh tools, and write files to the local directory.
- Sanitization: The skill includes a "Sensitive content check" (Phase 1, Step 4) to identify credentials or confidential items, but lacks specific sanitization for prompt injection patterns embedded within the text of the ingested documents.
- [COMMAND_EXECUTION]: The skill executes local system commands to retrieve context for the video script.
- Evidence: It utilizes
ghto fetch PR data andgitto analyze differences between references. While these are standard tools for developer agents, the commands are constructed based on user-provided PR numbers or git ref strings.
Audit Metadata