image-generation

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The SKILL.md instructions direct the agent to prepend a specific sentence starting with "CRITICAL:" to the generation prompt when handling Hebrew content. This is used to override default model behavior for layout and reading order. While functional, the use of mandatory override markers and specific instructions to modify prompt construction matches patterns associated with prompt injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the user and processes it through external AI service providers, creating a potential vector for indirect instructions.
  • Ingestion points: User-supplied prompt text and reference image asset paths provided as command-line arguments to generate_poster.ts and generate_video.ts.
  • Boundary markers: The scripts do not implement explicit delimiters or boundary instructions to separate user-provided content from the system-level prompts sent to the AI providers.
  • Capability inventory: The skill has capabilities for reading local files, performing network requests to external APIs, and writing generated media files to the local file system.
  • Sanitization: There is no sanitization or validation performed on the user-provided prompt strings or the content of the reference image assets before they are uploaded and processed by external models.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 09:13 PM
Security Audit — agent-trust-hub — image-generation