creativeclaw-nano-banana-2
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill utilizes a vendor-provided Model Context Protocol (MCP) tool hosted at
https://app.creativeclaw.co/mcp/chatgpt. This domain belongs to the author (creativeclawco), and the tool is intended for media and asset management.\n- [SAFE]: Instructions explicitly mandate that the agent should never loosen safety settings or attempt to bypass content refusals, promoting safe AI behavior.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data in the form of user-provided image references and attachments.\n - Ingestion points: External image URLs provided via
image_urlandextras.image_urls, along with ChatGPT attachments mentioned in the core workflow.\n - Boundary markers: The skill uses role-based labeling (e.g., 'base scene', 'identity') to organize references, but does not provide delimiters to separate untrusted data from the agent's instructions.\n
- Capability inventory: Access to the
creative-clawtoolset for media management and feedback, as well as image generation and editing capabilities.\n - Sanitization: The instructions include a manual inspection step ('Iteration and quality gate') for visual defects, but no programmatic sanitization or verification of external content is specified.
Audit Metadata