manim-composer

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a potential surface for indirect prompt injection by processing untrusted data from web research and user concepts to generate scene plans.\n
  • Ingestion points: Topic research in Phase 1 (web search) and clarification questions in Phase 2 (user input).\n
  • Boundary markers: The skill does not define boundary markers or explicit instructions to delimit and ignore potentially malicious content within the external research data.\n
  • Capability inventory: The skill possesses web search capabilities and the ability to generate markdown files (scenes.md).\n
  • Sanitization: The instructions do not specify any sanitization, filtering, or validation of content retrieved during the research phase.\n
  • Downstream impact: Maliciously crafted content from web searches could influence the generated scene plans, potentially affecting subsequent implementation steps when other skills or agents process the generated scenes.md file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 12:09 AM
Security Audit — agent-trust-hub — manim-composer