story-conti
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-provided movie scripts or advertising scenarios to generate visual frame descriptions and prompts. This creates an attack surface where malicious instructions embedded in the input text could influence the generated output. * Ingestion points: SKILL.md (Step 2) processes scenario scenes provided in the conversation context. * Boundary markers: The instructions do not define clear delimiters or warnings to ignore embedded instructions in the ingested data. * Capability inventory: The skill generates visual prompts and delegates generation execution to the moai-media toolset. * Sanitization: No explicit sanitization or filtering of external scenario content is mentioned before interpolation into frame prompts.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill references the external AI platform Higgsfield (higgsfield.ai) for manual content generation and coordinates with the moai-media sub-skill. These are documented as part of the intended professional workflow for video production.
Audit Metadata