clip-to-social
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists entirely of markdown instructions for an AI agent and does not include any executable scripts, binaries, or external dependencies.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data in the form of video transcripts, which presents a surface for indirect prompt injection. Ingestion points: The transcript or clip excerpt is passed as a user argument defined in SKILL.md. Boundary markers: There are no specific delimiters or instructions to ignore commands within the transcript content. Capability inventory: The skill has no defined tools, network access, or file system permissions. Sanitization: The input is processed as raw text without validation or escaping. Because the skill lacks any sensitive capabilities, the impact is limited to the content of the generated text drafts.
Audit Metadata