midjourney-video

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes user-supplied external image URLs for video frames, which presents a surface for indirect prompt injection attacks where malicious instructions could be embedded in the data sources.\n
  • Ingestion points: User-provided URLs for 'Starting frame' and 'Ending frame' parameters as described in the handoff template in SKILL.md.\n
  • Boundary markers: The instructions explicitly mandate that the human operator must 'Confirm that both URLs are approved and safe' and 'Freeze the exact handoff text' to prevent runtime modification.\n
  • Capability inventory: The agent possesses no automated execution capabilities, subprocess calls, file-write operations, or network access across the provided files; all execution is offloaded to a human operator.\n
  • Sanitization: The skill requires the human operator to hash source assets locally and manually verify account states and visibility settings before submission.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 02:28 PM
Security Audit — agent-trust-hub — midjourney-video