blitzreels-generation
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill dynamically loads generation capabilities and operational limits from the vendor's official domain at https://www.blitzreels.com/api/capabilities.json to ensure generation requests match current schema and limits.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input, such as topics or scripts, to generate AI media plans.
- Ingestion points: The workflow in SKILL.md (Step 4) accepts user-supplied topics or briefs for narration drafting and scene planning.
- Boundary markers: The skill uses a revision-based system with immutable plans (Step 5) to ensure that once a plan is drafted, it remains consistent throughout the approval process.
- Capability inventory: The skill possesses capabilities to create projects, generate assets, and trigger media animation through the vendor's REST API and CLI tools.
- Sanitization: Security risk is mitigated by a mandatory manual review step (Step 6) where the agent must present the drafted plan, factual notes, and estimated costs for approval before any media generation or animation occurs.
Audit Metadata