magic-hour-thumbnails

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data, including video transcripts, footage, and outlines, which could contain adversarial instructions designed to influence the agent's behavior during the analysis or generation phase.
  • Ingestion points: Video transcripts, outlines, footage, and source images provided by the user.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the source material.
  • Capability inventory: The skill utilizes image generation tools (ai_image_editor_create_image, ai_image_generator_create_image) and network upload capabilities (video_assets_generate_presigned_url).
  • Sanitization: No explicit sanitization or validation of the input text/metadata is described.
  • [EXTERNAL_DOWNLOADS]: The skill references the vendor's official MCP endpoint and documentation repositories for configuration and API usage.
  • Evidence: References to https://mcp.magichour.ai/ and the magichourhq GitHub organization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 05:09 PM
Security Audit — agent-trust-hub — magic-hour-thumbnails