seedance-filter

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process untrusted user input (blocked or degraded prompts) to generate a revised version, creating an indirect prompt injection surface.
  • Ingestion points: The skill processes the user's original prompt text within the Repair Method logic.
  • Boundary markers: The skill contains explicit 'Boundary Rule' and 'Boundary — read before anything else' sections that instruct the agent to refuse unsafe requests involving minors, illegal material, or graphic content.
  • Capability inventory: The skill is limited to text generation and does not define or request access to tools for file writing, network operations, or command execution.
  • Sanitization: The instructions include a specific 5-step repair method designed to identify and replace risky surface wording with professional, non-graphic production language.
  • [EXTERNAL_DOWNLOADS]: The skill references external support files for its operation.
  • Evidence: References to ../../references/directors-read.md, ../../references/filter-vocab.md, and ../../references/multilingual-community-examples.md are included in the instructions.
  • Context: These are local file references within the vendor's repository structure (emily2040) used to provide context and vocabulary for the prompt repair task.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 01:47 PM
Security Audit — agent-trust-hub — seedance-filter