creativeclaw-nano-banana-2

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill utilizes a vendor-provided Model Context Protocol (MCP) tool hosted at https://app.creativeclaw.co/mcp/chatgpt. This domain belongs to the author (creativeclawco), and the tool is intended for media and asset management.\n- [SAFE]: Instructions explicitly mandate that the agent should never loosen safety settings or attempt to bypass content refusals, promoting safe AI behavior.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data in the form of user-provided image references and attachments.\n
  • Ingestion points: External image URLs provided via image_url and extras.image_urls, along with ChatGPT attachments mentioned in the core workflow.\n
  • Boundary markers: The skill uses role-based labeling (e.g., 'base scene', 'identity') to organize references, but does not provide delimiters to separate untrusted data from the agent's instructions.\n
  • Capability inventory: Access to the creative-claw toolset for media management and feedback, as well as image generation and editing capabilities.\n
  • Sanitization: The instructions include a manual inspection step ('Iteration and quality gate') for visual defects, but no programmatic sanitization or verification of external content is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 12:38 PM
Security Audit — agent-trust-hub — creativeclaw-nano-banana-2