seedance-shotlist-director
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. It ingests untrusted user data (scripts, scene breakdowns) and interpolates this content into a generated HTML file (shotlist.html) without explicit instructions for sanitization or escaping.
- Ingestion points: User-provided scripts and scene breakdowns are processed and inserted into the {{SCENES_HTML}} template variable in SKILL.md.
- Boundary markers: The generated HTML lacks explicit boundary markers or escaping logic to differentiate between the agent's instructions and user-supplied content.
- Capability inventory: The agent has the capability to write files to the file system at /mnt/user-data/outputs/shotlist.html.
- Sanitization: No sanitization, validation, or escaping of the user-provided content is performed before interpolation into the HTML template.
Audit Metadata