higgsfield-content-factory

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted data from external sources during the research phase.\n
  • Ingestion points: Stage 1 (SKILL.md) scans Instagram, TikTok, and YouTube trends and fetches content from user-provided URLs to synthesize a content brief.\n
  • Boundary markers: There are no specified delimiters or instructions to ignore embedded commands within the ingested data.\n
  • Capability inventory: The agent can generate video and image assets, access financial transaction history, and interact with advertising platforms to schedule campaigns.\n
  • Sanitization: The instructions do not define methods for sanitizing or validating the retrieved social media data before it is processed by the model.\n- [EXTERNAL_DOWNLOADS]: The skill implements a dynamic tool installation workflow for ad platform integration.\n
  • Evidence: In publish-and-report-workflow.md, the agent is instructed to search for and offer installation of 'Meta Ads connectors' from an 'MCP connector registry'. This mechanism poses a risk of typosquatting or the installation of malicious tools if the underlying registry lacks strict verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 12:58 PM
Security Audit — agent-trust-hub — higgsfield-content-factory