auto-cartoon-animation-director
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides specific instructions to execute the higgsfield binary located at /.local/bin/higgsfield, creating a pathway for local command invocation with user-supplied parameters.
- [DATA_EXFILTRATION]: The skill requires access to project-specific directories in the user home folder (/AI Advertising/campaigns/gold), exposing local file system hierarchy and project content to the agent.
- [INDIRECT_PROMPT_INJECTION]: The agent is tasked with processing external product briefs and audio content which could contain adversarial instructions. 1. Ingestion points: Product briefs, workflow instructions, and audio recordings. 2. Boundary markers: None identified. 3. Capability inventory: Local command execution via higgsfield and file system read/write access. 4. Sanitization: No sanitization or validation mechanisms are described for untrusted inputs.
Audit Metadata