narrato-short

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest external data such as SRT subtitle files or drama descriptions. It lacks specific boundary markers or instructions to the agent to ignore any embedded directives within that external data, making it potentially vulnerable to indirect prompt injection.
  • Ingestion points: User-supplied subtitle content (SRT) and drama descriptions in SKILL.md.
  • Boundary markers: Absent; the skill does not instruct the agent to treat input strictly as data.
  • Capability inventory: The skill only generates text and JSON output; it does not possess capabilities for file writing, system command execution, or network operations.
  • Sanitization: No input validation or content filtering is implemented.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 04:25 PM
Security Audit — agent-trust-hub — narrato-short