seedance-pipeline
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious code, hidden commands, or credential exfiltration attempts were detected in the skill instructions.
- [INDIRECT_PROMPT_INJECTION]: The skill instructions specify the ingestion of multiple external reference files (e.g., api-status.md, model-name-map.md, api-workflow.md).
- Ingestion points: SKILL.md (Status Rule section).
- Boundary markers: None explicitly defined for these internal project references.
- Capability inventory: No executable scripts or tool-invocation capabilities are defined in this skill; it is purely instructional.
- Sanitization: The skill includes an explicit instruction under the 'Corpus-mining workflow' section to 'extract structure and vocabulary, not unsafe raw prompts', which serves as a safety filter for the agent.
Audit Metadata