storyboard-generator
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a legitimate tool for storyboard generation with no evidence of malicious behavior or security bypass attempts.
- [CREDENTIALS_UNSAFE]: The skill correctly manages API keys (GEMINI_API_KEY, FAL_KEY) using environment variables and a local credential manager utility, ensuring that no secrets are hardcoded in the repository.
- [PROMPT_INJECTION]: The skill processes untrusted user input from scenarios and character descriptions in scripts/generate_storyboard.py. It employs boundary markers such as JSON structural requirements and triple backtick delimiters to manage the context. Its capabilities include local file writing and network API calls, while sanitization relies on the safety filters of the underlying Gemini API and strict output formatting instructions.
- [REMOTE_CODE_EXECUTION]: Network operations are limited to communicating with official AI service endpoints. The script uses dynamic path resolution for local imports to modularize access to shared repository tools, which is a standard pattern in this environment.
Audit Metadata