explainer

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill has a vulnerability surface for indirect prompt injection as it fetches and processes content from untrusted external sources, including arbitrary website URLs and GitHub repositories.
  • Ingestion points: Data enters the agent's context through WebFetch (for website content) and the gh tool (for repository metadata and README files) as specified in the SKILL.md workflow.
  • Boundary markers: The instructions do not define clear delimiters or specific guardrail prompts to isolate this untrusted content from the narration generation logic.
  • Capability inventory: The agent has extensive capabilities to generate and modify media, including generate_speech, generate_lipsync, capture_website, edit_pip, and add_captions.
  • Sanitization: There is no evidence of content sanitization or filtering of the fetched data before it is interpolated into prompts for authoring the video's beat sheet and spoken narration.
  • [DATA_EXFILTRATION]: The skill instructs users to upload local image files to a public URL using the upload_asset tool as a workaround for platform-specific image handling limitations. While intended for avatars, this pattern encourages the transmission of local files to an external service, which could lead to accidental exposure of sensitive data if a user provides incorrect file paths.
  • [DYNAMIC_EXECUTION]: The skill uses the capture_website tool to execute custom CSS and perform scrolling operations via JavaScript evaluation in a browser environment. While this is necessary for the skill's purpose of recording web walkthroughs, it involves the dynamic interaction of generated code with untrusted external web content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:28 AM