character-design

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection by design, as it is intended to process untrusted external data such as raw story text, novel/IP descriptions, and outlines to generate character designs and prompts for image/video models. An attacker could embed malicious instructions within narrative text that attempt to manipulate the resulting prompts or bypass safety guidelines during downstream generation.\n
  • Ingestion points: The skill explicitly processes user-supplied 'raw story text', 'novel/IP', and 'loose outlines' in the SKILL.md file to derive character narrative functions and visual anchors.\n
  • Boundary markers: There are no specific delimiters or boundary markers defined in the instructions to protect the agent from interpreting instructions that might be embedded within the ingested story data.\n
  • Capability inventory: The skill generates structured character packets, prompt anchors, and specialized image-generation prompts (SKILL.md, SECTIONS/06_AI提示词模板.md) which may be automatically passed to other agent tools or generative models.\n
  • Sanitization: The instructions do not include specific validation or sanitization steps to filter out potential prompt injection patterns from the input narrative data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 05:01 PM
Security Audit — agent-trust-hub — character-design