alterlab-nmc-multimedia-story

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core operational design.
  • Ingestion points: The agent is explicitly instructed to "search the web" for storytelling examples and "read existing project files" (SKILL.md) to gather context.
  • Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from executing instructions found within the untrusted external data it retrieves.
  • Capability inventory: The agent has the ability to search the web, read files from the project directory, and write new markdown files to the local environment.
  • Sanitization: The instructions lack any requirement for the agent to sanitize or validate content fetched from web searches or local project files before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 11:44 PM
Security Audit — agent-trust-hub — alterlab-nmc-multimedia-story