creativeclaw-seedance-2-5

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided external media (images, videos, audio) which are interpolated into the prompt context via tokens. \n
  • Ingestion points: External media files imported via the Creative Claw platform as described in SKILL.md. \n
  • Boundary markers: The skill advises setting agentic_prompting: false for authored content, which acts as a partial boundary but does not fully mitigate risks from data embedded in the media assets. \n
  • Capability inventory: The agent interacts with video generation models and feedback submission tools. \n
  • Sanitization: No specific sanitization or filtering of external media content is documented. \n- [EXTERNAL_DOWNLOADS]: The skill configuration in agents/openai.yaml includes an MCP tool URL. \n
  • Description: The tool is hosted at https://app.creativeclaw.co/mcp/chatgpt, which belongs to the vendor's domain (creativeclaw.co) and is used for its defined media and feedback operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 12:38 PM
Security Audit — agent-trust-hub — creativeclaw-seedance-2-5