seedance-filter
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process untrusted user input (blocked or degraded prompts) to generate a revised version, creating an indirect prompt injection surface.
- Ingestion points: The skill processes the user's original prompt text within the
Repair Methodlogic. - Boundary markers: The skill contains explicit 'Boundary Rule' and 'Boundary — read before anything else' sections that instruct the agent to refuse unsafe requests involving minors, illegal material, or graphic content.
- Capability inventory: The skill is limited to text generation and does not define or request access to tools for file writing, network operations, or command execution.
- Sanitization: The instructions include a specific 5-step repair method designed to identify and replace risky surface wording with professional, non-graphic production language.
- [EXTERNAL_DOWNLOADS]: The skill references external support files for its operation.
- Evidence: References to
../../references/directors-read.md,../../references/filter-vocab.md, and../../references/multilingual-community-examples.mdare included in the instructions. - Context: These are local file references within the vendor's repository structure (emily2040) used to provide context and vocabulary for the prompt repair task.
Audit Metadata