product-studio-visual

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the agent to access and inspect media from several external domains including goodcase.ai, liblib.art, liblib.cloud, youmind.com, xiaoyaoyou.com, and x.com. These are used as reference material for visual styling and workflow grounding.
  • Evidence: Found in references/cases.md where multiple external links are provided for "finished media" and "original source".
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it ingests and processes content from external web sources to influence its output generation.
  • Ingestion points: External URLs provided in references/cases.md are accessed via browser, video, or image tools as instructed in SKILL.md.
  • Boundary markers: No explicit boundary markers or "ignore embedded instructions" warnings are present to delimit external content from internal agent logic.
  • Capability inventory: The agent is explicitly instructed to use an "available image, video, or browser tool" to inspect finished media at runtime in SKILL.md.
  • Sanitization: The skill does not define specific sanitization, filtering, or validation logic for the content fetched from the external reference URLs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 06:37 AM
Security Audit — agent-trust-hub — product-studio-visual