video-prompt-schema
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted storyboard scripts or verbal descriptions from users to populate its internal schema.
- Ingestion points: User-provided storyboard scripts and descriptions processed in the '工作流程' section of
SKILL.md. - Boundary markers: No delimiters or 'ignore embedded instructions' warnings are present to isolate the processed data from agent instructions.
- Capability inventory: The skill performs text transformation and JSON formatting; it does not have shell execution or network access capabilities.
- Sanitization: There is no evidence of sanitization or escaping of the user-provided content before interpolation into the final output prompts.
- [DATA_EXFILTRATION]: The skill instructions reference access to a specific local file path for retrieval of examples.
- Evidence: The
SKILL.mdfile points to~/.claude/case-library/as a source for existing case references. - Context: This involves localized filesystem access within the agent's expected working environment; however, it does not target sensitive system credentials or include instructions for remote exfiltration.
- [NO_CODE]: The skill package does not contain any executable scripts or binary files, relying entirely on Markdown-based instructions and a static JSON schema for its operation.
Audit Metadata