editorial-portrait-composition
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it requires reading and processing external data from
references/cases.md(Category 8). - Ingestion points: The agent is explicitly instructed to read
references/cases.mdon every invocation to select an 'anchor Case'. - Boundary markers: The instructions include a 'Required evidence gate' and safety sections to prevent 'superficial copying' and 'impersonation', acting as soft boundaries.
- Capability inventory: The skill uses image/browser tools to inspect media and generates text-based image prompts; it does not have direct file-write or system-level execution capabilities.
- Sanitization: There is no explicit technical sanitization (like JSON schema validation) of the external case data beyond the LLM's internal filters and the 'Preserve / Replace / Avoid' logic.
Audit Metadata