content-director

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted social media data through mcp__plugin_pika_pika__scrape_social and mcp__plugin_pika_pika__capture_website across its playbooks (SKILL.md, formats/talking.md, etc.). While explicit boundary markers and text sanitization are not documented, the skill implements a mandatory identity-confirmation gate to verify creator handles before synthesizing profiles. It maintains extensive capabilities for automated video editing and AI generation using Pika's MCP toolset.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: Video recordings are uploaded to the vendor's MCP infrastructure (mcp.pika.me) for processing. This is a functional requirement for the skill's editing capabilities. The provided teleprompter.html application enforces origin-validation checks to ensure that user data is exfiltrated only to authorized Pika-Labs endpoints.
  • [COMMAND_EXECUTION]: The skill makes extensive use of mcp__plugin_pika_pika__* tools for video transcoding, AI motion generation (Seedance, Kling), and audio mixing. These are legitimate platform-integrated tools used to achieve the skill's production goals.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with official vendor resources such as teleprompter.pika.bot and mcp.pika.me to manage the video recording and production lifecycle. These references are neutral and consistent with the established vendor identity.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 06:29 PM
Security Audit — agent-trust-hub — content-director