video-scriptwriter
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The script
scripts/generate_script.pypossesses an indirect prompt injection surface in its script generation logic. - Ingestion points: User input from the
--topicand--instructionscommand-line arguments are ingested and used to construct the LLM prompt in thebuild_promptfunction. - Boundary markers: The prompt construction lacks clear boundary markers or delimiters to isolate user-supplied text from the system instructions.
- Capability inventory: The script performs file-write operations (
scenes.json) and network requests to the Gemini API. - Sanitization: The user-supplied strings are interpolated into the prompt without escaping or validation.
Audit Metadata