magic-hour-music-video

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill exclusively utilizes domains, repositories, and API endpoints owned by the verified vendor magichourhq (including magichour.ai, mcp.magichour.ai, and github.com/magichourhq), which is appropriate for its stated functionality.
  • [SAFE]: The instructions demonstrate good security hygiene by explicitly advising the agent to perform file uploads to presigned URLs without including the API bearer token, preventing unnecessary credential exposure to storage infrastructure.
  • [SAFE]: Technical instructions provide clear guardrails that prevent the agent from fabricating MCP endpoints or allowing user-supplied lyrics to override the skill's operational logic or technical parameters.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied text (phrases and lyrics) as part of its core functionality. While this creates a potential attack surface, the instructions include explicit boundary markers and safety constraints that instruct the agent to interpret these inputs strictly as creative direction rather than executable instructions, effectively mitigating the risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 08:30 AM
Security Audit — agent-trust-hub — magic-hour-music-video