explainer
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill has a vulnerability surface for indirect prompt injection as it fetches and processes content from untrusted external sources, including arbitrary website URLs and GitHub repositories.
- Ingestion points: Data enters the agent's context through
WebFetch(for website content) and theghtool (for repository metadata and README files) as specified in the SKILL.md workflow. - Boundary markers: The instructions do not define clear delimiters or specific guardrail prompts to isolate this untrusted content from the narration generation logic.
- Capability inventory: The agent has extensive capabilities to generate and modify media, including
generate_speech,generate_lipsync,capture_website,edit_pip, andadd_captions. - Sanitization: There is no evidence of content sanitization or filtering of the fetched data before it is interpolated into prompts for authoring the video's beat sheet and spoken narration.
- [DATA_EXFILTRATION]: The skill instructs users to upload local image files to a public URL using the
upload_assettool as a workaround for platform-specific image handling limitations. While intended for avatars, this pattern encourages the transmission of local files to an external service, which could lead to accidental exposure of sensitive data if a user provides incorrect file paths. - [DYNAMIC_EXECUTION]: The skill uses the
capture_websitetool to execute custom CSS and perform scrolling operations via JavaScript evaluation in a browser environment. While this is necessary for the skill's purpose of recording web walkthroughs, it involves the dynamic interaction of generated code with untrusted external web content.
Audit Metadata