avkit

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements video playback and automated frame analysis features, which create an attack surface for instructions embedded in media content.
  • Ingestion points: External media URLs and content processed via AVPlayer and AVPlayerViewController (referenced in SKILL.md and references/avkit-patterns.md).
  • Boundary markers: The implementation patterns do not utilize delimiters or specific instructions to disregard content found within the media data.
  • Capability inventory: The skill specifically enables and configures allowsVideoFrameAnalysis for types such as .text and .machineReadableCode in references/avkit-patterns.md.
  • Sanitization: The provided patterns lack logic for sanitizing or validating information extracted from the video frames.
  • [METADATA_POISONING]: The skill metadata and reference sections use documentation links pointing to a parody domain rather than official vendor documentation.
  • Evidence: Multiple links in the References section of SKILL.md redirect to https://sosumi.ai/documentation/... instead of the expected official vendor documentation sites.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:59 AM
Security Audit — agent-trust-hub — avkit