magic-hour-thumbnails
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data, including video transcripts, footage, and outlines, which could contain adversarial instructions designed to influence the agent's behavior during the analysis or generation phase.
- Ingestion points: Video transcripts, outlines, footage, and source images provided by the user.
- Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the source material.
- Capability inventory: The skill utilizes image generation tools (
ai_image_editor_create_image,ai_image_generator_create_image) and network upload capabilities (video_assets_generate_presigned_url). - Sanitization: No explicit sanitization or validation of the input text/metadata is described.
- [EXTERNAL_DOWNLOADS]: The skill references the vendor's official MCP endpoint and documentation repositories for configuration and API usage.
- Evidence: References to
https://mcp.magichour.ai/and themagichourhqGitHub organization.
Audit Metadata