casting-agent

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/casting_agent.py uses subprocess.run to execute internal tasks and sanity checks using the current python executable and relative paths.\n- [PROMPT_INJECTION]: The skill ingests untrusted story context and entity descriptions (Category 8 surface). Ingestion points: story_contract.md and visual_entities.json. Boundary markers: None. Capability inventory: Subprocess execution, file writes, and delegated network search.\n- [DATA_EXFILTRATION]: The _write_package_inputs function reads local files based on paths provided in input JSON documents, which could lead to unauthorized data exposure if input files are malicious.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — casting-agent