magic-hour-character-consistency
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external character sheets and reference images, which introduces a surface for indirect prompt injection if these input files contain malicious instructions.\n
- Ingestion points: Character traits and approval images are read from local storage and user-provided character sheets.\n
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore' commands to isolate instructions that might be embedded within the character data.\n
- Capability inventory: The skill invokes image and video generation tools and performs network uploads to vendor-provided URLs.\n
- Sanitization: There is no technical sanitization or validation of character sheet content before it is used in generation prompts.\n- [EXTERNAL_DOWNLOADS]: The skill links to official documentation, API schemas, and an MCP server hosted on the vendor's official domain (magichour.ai) and GitHub repository (magichourhq). These references are legitimate resources provided by the skill author to facilitate platform usage.
Audit Metadata