ai-podcast

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The instructions describe a legitimate multi-step process for generating AI media content. All commands use the platform's structured tool invocation system (infsh app run).
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes an example for training an AI identity using a list of user-provided image URLs. This is a functional requirement for the specific AI service (phota/train) and does not involve downloading executable code.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves processing user-provided text for scripts and image URLs for avatar training. This creates an ingestion surface for external data. 1. Ingestion points: phota/train (image URLs), inworld/text-to-speech-2 (script text). 2. Boundary markers: None identified. 3. Capability inventory: Execution of AI generation tasks via infsh app run and Bash. 4. Sanitization: Not explicitly implemented in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 01:13 PM
Security Audit — agent-trust-hub — ai-podcast