media-generator

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface where untrusted data from user instructions or external files is processed to generate media content.\n
  • Ingestion points: Untrusted data enters the agent context through the --topic and --prompt arguments in scripts such as tools/generate_diagram.py and tools/nanobanana.py, and via reading local files like article.txt.\n
  • Boundary markers: Delimiters (such as XML tags or explicit markers) and 'ignore embedded instructions' warnings are absent, increasing the risk that instructions inside the data could influence the agent's behavior.\n
  • Capability inventory: The skill possesses the ability to write files to the local file system (docs/generated/) and perform network operations to interact with Google's Generative AI APIs.\n
  • Sanitization: There is no evidence of sanitization, validation, or escaping of external content before it is interpolated into the prompts for image generation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — media-generator