create-storyboard

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill frequently uses the subprocess module to execute local commands and scripts. This includes using ffmpeg for media processing in animatic_assembler.py and invoking sibling skills by executing their respective run.py scripts (e.g., in memory_bridge.py, research_bridge.py, and panel_generator.py). While these calls are parameterized as lists (mitigating direct shell injection), they represent a broad surface for local command execution based on the skill's logic.
  • [PROMPT_INJECTION]: The skill processes untrusted screenplay markdown files provided by the user, which serves as a surface for Indirect Prompt Injection. Content within specific markers like [CAMERA:], [LIGHTING:], or [NOTE:] is extracted and interpolated into natural language suggestions provided to the agent/user during the collaboration phase. A malicious screenplay could include instructions designed to override agent behavior when the agent processes these suggestions.
  • Ingestion points: Screenplay markdown files read from the local file system in screenplay_parser.py.
  • Boundary markers: The skill uses tag-based markers (e.g., [CAMERA:]) for extraction but lacks robust sanitization or delimiters to prevent embedded instructions from being interpreted as authoritative by the agent during the suggestion loop.
  • Capability inventory: Subprocess execution (FFmpeg, local python scripts), file system read/write (reading screenplays, writing panels and sessions), and indirect network access via the dogpile research skill.
  • Sanitization: Minimal. The extracted text is directly included in natural language templates without escaping or instruction-ignoring wrappers.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — create-storyboard