media-generator
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface where untrusted data from user instructions or external files is processed to generate media content.\n
- Ingestion points: Untrusted data enters the agent context through the
--topicand--promptarguments in scripts such astools/generate_diagram.pyandtools/nanobanana.py, and via reading local files likearticle.txt.\n - Boundary markers: Delimiters (such as XML tags or explicit markers) and 'ignore embedded instructions' warnings are absent, increasing the risk that instructions inside the data could influence the agent's behavior.\n
- Capability inventory: The skill possesses the ability to write files to the local file system (
docs/generated/) and perform network operations to interact with Google's Generative AI APIs.\n - Sanitization: There is no evidence of sanitization, validation, or escaping of external content before it is interpolated into the prompts for image generation.
Audit Metadata