baseball-trend
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill employs strong instructional markers like 'CRITICAL' and 'Hardlock' within the prompts sent to the image and video generation models (GPT-Image-2 and Kling). These are standard prompt engineering techniques used to ensure the AI follows specific aesthetic and likeness constraints and are not attempts to bypass the primary agent's safety protocols.
- [DATA_EXFILTRATION]: The skill manages user-provided names and images as part of its core functionality. It utilizes an 'upload_asset' tool to convert local files into public URLs for processing by the media generation engines. This is a functional requirement for the Pika MCP pipeline and does not involve unauthorized data access or exfiltration to unknown third parties.
- [COMMAND_EXECUTION]: There is no evidence of unauthorized shell command execution. A reference to the 'convert' utility is found in the documentation under 'Failure modes' as a manual suggestion for users to fix image metadata issues, but the skill does not attempt to execute this command automatically.
- [SAFE]: The skill does not contain any obfuscated code, hidden URLs, persistence mechanisms, or hardcoded credentials. The author context (Pika-Labs) is consistent with the tools being used (mcp__pika), and the behavior aligns with the stated purpose of creating broadcast-themed media.
Audit Metadata