klingai-text-to-video

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the transmission of user-provided text prompts to the Kling AI API, creating a potential surface for indirect prompt injection attacks. \n- Ingestion points: User prompts are ingested in multiple files including SKILL.md, references/basic-text-to-video.md, and references/advanced-parameters.md. \n- Boundary markers: The code examples do not demonstrate the use of delimiters or systemic instructions to mitigate the impact of malicious content within the prompt data. \n- Capability inventory: The skill possesses network communication capabilities (via requests and aiohttp) and shell execution permissions (via Bash scoped to npm packages). \n- Sanitization: There is no evidence of prompt sanitization or validation logic in the provided reference implementations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:46 AM
Security Audit — agent-trust-hub — klingai-text-to-video