alterlab-cdm-subtitle-loc

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it is instructed to ingest and process data from untrusted external sources.
  • Ingestion points: The skill is instructed to "Search the web for current data" and "Read existing project files for context" (such as scripts and dialogue lists) in the 'Workflow' section of SKILL.md.
  • Boundary markers: There are no explicit instructions or delimiters (like XML tags or specific 'ignore instructions' warnings) to prevent the agent from accidentally following commands embedded within the external files or search results it processes.
  • Capability inventory: The skill has the capability to perform web searches and write files to the project directory (e.g., .srt and .vtt files).
  • Sanitization: No explicit sanitization, validation, or filtering of the external data is specified in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 11:44 PM
Security Audit — agent-trust-hub — alterlab-cdm-subtitle-loc