podcast-generation
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided content to generate conversational scripts, creating a surface where embedded instructions in the source text could influence agent actions.\n
- Ingestion points: As described in
SKILL.md, the skill takes arbitrary source content (articles, reports, documentation) as input to be converted into a podcast.\n - Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially malicious embedded commands within the input content.\n
- Capability inventory: The skill executes
scripts/generate.pywhich performs network operations (POST requests to Volcengine and MiniMax TTS APIs) and writes audio and transcript files to the/mnt/user-data/directory.\n - Sanitization: While the skill provides guidelines for tone and style, it lacks technical sanitization or validation mechanisms to filter adversarial instructions from the input text before processing.
Audit Metadata