storyboard-creation

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the belt CLI tool, the official interface for the inference.sh platform. The allowed-tools frontmatter field restricts the execution environment to only allow belt commands, representing a least-privilege security configuration.
  • [EXTERNAL_DOWNLOADS]: The skill references a setup guide located in the author's GitHub repository (github.com/inference-sh/skills) and provides instructions to install the belt-sh/cli tool. These are verified vendor resources consistent with the skill's origin.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied scene descriptions for image generation. The risk is minimized by the skill's structure and the underlying safety guardrails of the inference platform.
  • Ingestion points: Visual descriptions and prompt variables in SKILL.md used within CLI commands.
  • Boundary markers: Uses structured JSON (--input '{...}') to separate prompt content from command-line arguments.
  • Capability inventory: Accesses remote inference APIs for image generation and performs local image stitching.
  • Sanitization: Relies on the internal safety filters and content moderation of the target image generation models.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:12 AM
Security Audit — agent-trust-hub — storyboard-creation