create-shot-list

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted text inputs to generate a structured scene manifest that drives downstream automated video generation. This creates an attack surface where malicious instructions embedded in the input data could influence agent behavior or subvert the rendering process.\n
  • Ingestion points: The skill instructions specify the use of external input files including script.md, idea-brief.md, targeting-spec.md, and brand-voice.md.\n
  • Boundary markers: Absent. There are no instructions to use delimiters or ignore-previous-instruction headers when interpolating these untrusted inputs into the manifest.\n
  • Capability inventory: The skill utilizes a local script (scripts/build_edit_plan.py) for file operations and references downstream atoms for video and graphic rendering.\n
  • Sanitization: Absent. No validation or sanitization logic is requested or implemented for the content of the input files before they are included in the generated scene-manifest.yml artifact.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 04:39 PM
Security Audit — agent-trust-hub — create-shot-list