higgsfield-content-factory
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted data from external sources during the research phase.\n
- Ingestion points: Stage 1 (SKILL.md) scans Instagram, TikTok, and YouTube trends and fetches content from user-provided URLs to synthesize a content brief.\n
- Boundary markers: There are no specified delimiters or instructions to ignore embedded commands within the ingested data.\n
- Capability inventory: The agent can generate video and image assets, access financial transaction history, and interact with advertising platforms to schedule campaigns.\n
- Sanitization: The instructions do not define methods for sanitizing or validating the retrieved social media data before it is processed by the model.\n- [EXTERNAL_DOWNLOADS]: The skill implements a dynamic tool installation workflow for ad platform integration.\n
- Evidence: In
publish-and-report-workflow.md, the agent is instructed to search for and offer installation of 'Meta Ads connectors' from an 'MCP connector registry'. This mechanism poses a risk of typosquatting or the installation of malicious tools if the underlying registry lacks strict verification.
Audit Metadata