creativeclaw-build-film
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes project-related data like briefs and scripts retrieved from external storage tools.
- Ingestion points: Data enters the agent context via list_film_projects and get_film_project in SKILL.md.
- Boundary markers: No specific delimiters are used to separate external project data from instructions.
- Capability inventory: The skill utilizes powerful tools for video and audio generation and media merging.
- Sanitization: The instructions do not define sanitization for data pulled from project records.
- [DYNAMIC_EXECUTION]: The skill supports HTML-based video rendering using the render_html_video tool.
- The instructions mitigate risk by directing the agent to only use this tool upon explicit user request.
Audit Metadata