create-ksml
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. Ingestion points: The adapter.py script reads untrusted movie script data from a JSON file provided via the --script parameter. Boundary markers: The skill does not implement boundary markers or instructions to ignore embedded commands when generating the project.ksml output. Capability inventory: The skill has the ability to write to the file system and delete directories (shutil.rmtree, shutil.copy2) within adapter.py. Sanitization: There is no evidence of sanitization or escaping of the user-provided script content before it is interpolated into the YAML manifest structure.
- [COMMAND_EXECUTION]: File System Management. The skill programmatically deletes the export directory using shutil.rmtree and copies asset files using shutil.copy2 based on user-supplied paths, which is expected behavior for its stated purpose but involves direct file system interaction.
Audit Metadata