carocut-media-visual

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes resource definitions from an external configuration file (manifests/resources.yaml) and uses them as input for search queries and AI generation prompts, creating an indirect prompt injection surface.
  • Ingestion points: manifests/resources.yaml
  • Boundary markers: Absent (strings are interpolated directly into prompts)
  • Capability inventory: Media retrieval and AI generation via the videos_search and images_generate tools.
  • Sanitization: Absent.
  • [COMMAND_EXECUTION]: The skill includes a Python script snippet designed to be executed for manual validation of sprite sheet dimensions using the Pillow library. This is a legitimate utility function for ensuring asset compatibility with video production tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 09:07 AM
Security Audit — agent-trust-hub — carocut-media-visual