cover
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides usage examples for a command-line interface tool called 'motif' to generate image files from prompts. This is documented functionality for the user to execute manually.
- [PROMPT_INJECTION]: The skill reads external project materials (README, theme files, character descriptions) to synthesize cover art concepts. This creates a surface for indirect prompt injection where malicious instructions inside project files could attempt to influence the agent's prompt generation behavior.
- Ingestion points: README, themes, characters, world, and tone files.
- Boundary markers: None identified in the skill instructions.
- Capability inventory: Generates text-based image generation prompts.
- Sanitization: No explicit validation or filtering of the ingested project content is performed before interpolation.
Audit Metadata