pov-vlog-presence

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill references multiple external URLs on domains such as goodcase.ai and youmind.com to retrieve case evidence and media assets. These network operations target domains outside the standard whitelist but are functionally relevant to the skill's purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from references/cases.md to inform its prompt generation workflow. This ingestion surface is susceptible to indirect prompt injection as it lacks explicit boundary markers or sanitization logic.
  • Ingestion points: The file references/cases.md provides prompt excerpts and summaries used to construct new artifacts.
  • Boundary markers: Absent; there are no specific instructions to ignore malicious directives within the case evidence.
  • Capability inventory: The agent is instructed to generate executable video prompts and use available image, video, or browser tools to inspect external media.
  • Sanitization: Absent; the content from the evidence file is directly used to define visual traits and structural elements.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 06:37 AM
Security Audit — agent-trust-hub — pov-vlog-presence