report-generator

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external JSON data (breakdown.json and hook_analysis.json) and interpolates it directly into Markdown report templates. While there is no immediate execution of this data, it creates a surface where malicious instructions embedded in the video analysis fields (like visual_comment or reason) could influence the behavior of downstream agents or applications that render and process the generated Markdown report.
  • Ingestion points: The scripts/generate_report.py script reads data from files provided via command-line arguments.
  • Boundary markers: None identified. Data is directly formatted into the report string.
  • Capability inventory: The skill performs file reads and standard output writes via scripts/generate_report.py. It does not perform network operations or subprocess execution.
  • Sanitization: The script performs basic truncation on visual_content but does not sanitize other fields for Markdown injection or control characters.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — report-generator