scroll-world-storytelling

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill processes user-supplied articles and case studies to map narrative beats. It contains explicit instructions to maintain factual integrity and prohibits the fabrication of metrics or testimonials. It also requires user approval before using external video generation APIs (such as Grok Imagine).
  • [EXTERNAL_DOWNLOADS]: The skill follows security best practices by requiring local, pinned dependencies for frameworks like Three.js. The instructions explicitly state that the agent should not depend on remote CDNs for core renderers, reducing the risk of supply chain attacks.
  • [COMMAND_EXECUTION]: The documentation provides benign shell command templates for using ffmpeg to encode video assets locally. These commands are restricted to media optimization (e.g., setting keyframe intervals for scrubbing) and do not involve untrusted inputs or risky flags.
  • [INDIRECT_PROMPT_INJECTION]: As the skill is designed to ingest and transform untrusted third-party text (articles/narratives), it possesses an inherent attack surface for indirect prompt injection. However, the skill provides mitigation strategies, such as instructions to paraphrase source material and maintain strict adherence to the provided story map beats, which helps compartmentalize external data from the agent's internal logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 05:24 PM
Security Audit — agent-trust-hub — scroll-world-storytelling