vr-avatar-engineer

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest untrusted data from external websites and technical papers using mcp__firecrawl__firecrawl_search and WebFetch.\n
  • Ingestion points: mcp__firecrawl__firecrawl_search and WebFetch tools (referenced in SKILL.md frontmatter and MCP Integrations table).\n
  • Boundary markers: Absent. The instructions do not specify the use of delimiters or warnings to ignore instructions within the fetched content.\n
  • Capability inventory: The agent has access to Bash, Write, Edit, and mcp__stability-ai__stability-ai-generate-image.\n
  • Sanitization: Absent. There are no instructions for validating or escaping the external content before processing it with the available tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 07:23 PM
Security Audit — agent-trust-hub — vr-avatar-engineer