novoads-pixar-storyboard-ad

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use local ffmpeg and ffprobe for video trimming, audio mixing, and concatenation. These commands use standardized naming conventions like beatN and master.mp4 to mitigate shell injection risks during local assembly.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with the novoads.ai domain for AI generation tasks including video, image, voice, music, and captions. These are legitimate vendor-controlled endpoints associated with the author.
  • [PROMPT_INJECTION]: The skill implements safety measures by explicitly instructing the agent to avoid generating copyrighted content, inventing fake reviews, or using trademarked studio names. It also provides structured prompt templates to ensure consistent and safe output.
  • [PROMPT_INJECTION]: The skill processes user-provided product data and media, creating an attack surface for indirect prompt injection. Mandatory Evidence Chain: 1. Ingestion points: User prompt and product photos. 2. Boundary markers: Explicit template-based prompt construction and guidance. 3. Capability inventory: Comprehensive generation toolset and shell execution via ffmpeg. 4. Sanitization: Relies on prompt-level constraints and templates rather than active input filtering. The severity is assessed as low.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 06:27 PM
Security Audit — agent-trust-hub — novoads-pixar-storyboard-ad