character-design
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection by design, as it is intended to process untrusted external data such as raw story text, novel/IP descriptions, and outlines to generate character designs and prompts for image/video models. An attacker could embed malicious instructions within narrative text that attempt to manipulate the resulting prompts or bypass safety guidelines during downstream generation.\n
- Ingestion points: The skill explicitly processes user-supplied 'raw story text', 'novel/IP', and 'loose outlines' in the
SKILL.mdfile to derive character narrative functions and visual anchors.\n - Boundary markers: There are no specific delimiters or boundary markers defined in the instructions to protect the agent from interpreting instructions that might be embedded within the ingested story data.\n
- Capability inventory: The skill generates structured character packets, prompt anchors, and specialized image-generation prompts (
SKILL.md,SECTIONS/06_AI提示词模板.md) which may be automatically passed to other agent tools or generative models.\n - Sanitization: The instructions do not include specific validation or sanitization steps to filter out potential prompt injection patterns from the input narrative data.
Audit Metadata