broll-assets
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads media assets from Pexels, which is a well-known stock photography and video service.
- [PROMPT_INJECTION]: The skill ingests untrusted data from user-provided media and external Pexels API responses, creating an attack surface for indirect prompt injection. Ingestion points: User material and external asset requests in SKILL.md. Boundary markers: None identified. Capability inventory: Writing files to the broll-production/02-assets/ directory. Sanitization: Not detailed beyond inspection requirements.
Audit Metadata