music-video-subtitle-generator

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted user content, such as lyrics and music, and incorporates them into instructions for subsequent agents (video, image, and editing tools).
  • Ingestion points: The skill reads user-provided music, lyrics, and character/scene references as described in SKILL.md.
  • Boundary markers: While the skill utilizes a modular prompt template (Step 5), it lacks explicit instructions to sanitize or use specific safety delimiters for user-provided strings within the generated output.
  • Capability inventory: The agent can write data to canvas text nodes and delegate complex media generation tasks to specialized Hub agents.
  • Sanitization: No sanitization or validation logic is specified for the input data before it is interpolated into the final prompt script.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 02:22 PM
Security Audit — agent-trust-hub — music-video-subtitle-generator