video-prompt-writer
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: Exposure of local file system structure. The file
SKILL.mdcontains a hardcoded absolute path to a specific user's document folder (/Users/baimengke/Documents/白梦客知识库/02-创作方法论/A-视频生成专项/). While not an active exfiltration, this leaks information about the author's or intended user's environment. - [PROMPT_INJECTION]: Vulnerability to indirect prompt injection via the 'Evolution Flow'. The skill instructs the agent in
evolution/evolution-log.mdandSKILL.mdto read case studies (evolution/cases.md) and 'learnings' to update its own core instructions (SKILL.md). - Ingestion points: Data from
evolution/cases.mdandevolution/learnings.mdwhich are populated from user-provided 'success/failure' cases. - Boundary markers: Absent. There are no instructions to disregard embedded commands within the cases being analyzed.
- Capability inventory: The agent is explicitly given the task to 'Update SKILL.md body content' based on its analysis of external data.
- Sanitization: Absent. The skill lacks validation or escaping for the content being used to update its own instructions.
Audit Metadata