podcast-generation

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided content to generate conversational scripts, creating a surface where embedded instructions in the source text could influence agent actions.\n
  • Ingestion points: As described in SKILL.md, the skill takes arbitrary source content (articles, reports, documentation) as input to be converted into a podcast.\n
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially malicious embedded commands within the input content.\n
  • Capability inventory: The skill executes scripts/generate.py which performs network operations (POST requests to Volcengine and MiniMax TTS APIs) and writes audio and transcript files to the /mnt/user-data/ directory.\n
  • Sanitization: While the skill provides guidelines for tone and style, it lacks technical sanitization or validation mechanisms to filter adversarial instructions from the input text before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:13 PM