higgsfield-marketing-studio

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill contains detailed documentation, parameter schemas, and production-ready prompt examples for the Higgsfield Marketing Studio video generation platform. No malicious code or obfuscation was found in the analyzed files.
  • [SAFE]: Mentioned MCP tools such as generate_video and show_marketing_studio are used within the context of their intended functionality for marketing content creation and asset management. The transactions() tool is correctly documented for checking billing spend, which is an expected administrative function.
  • [PROMPT_INJECTION]: The skill documents features for ingesting data from external URLs via the show_marketing_studio(action='fetch', url='...') tool call, which represents an indirect prompt injection surface.
  • Ingestion points: External product page URLs are processed in SKILL.md §3 and §6.
  • Boundary markers: The documentation does not specify explicit boundary markers or ignore-embedded-instructions warnings for the fetched content.
  • Capability inventory: The skill uses generate_video and show_marketing_studio for content creation and entity management.
  • Sanitization: No specific sanitization or validation methods for external content are mentioned in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 11:31 PM
Security Audit — agent-trust-hub — higgsfield-marketing-studio