xyq-short-drama-skill

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it ingests and processes text output (readable_text) generated by a remote backend agent to drive user interactions and workflow decisions.
  • Ingestion points: The readable_text field returned by the get-thread command in SKILL.md is used to determine the next steps and generate questions for the user.
  • Boundary markers: There are no explicit instructions or delimiters used to isolate the server-provided text from the agent's internal logic.
  • Capability inventory: The skill has the capability to execute shell commands (pippit-tool-cli) and perform file system writes (download-result).
  • Sanitization: The instructions include logic for filtering and cleaning workflow options based on the drama creation stage, but do not specify security-focused sanitization for the raw text content.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install its required tooling via npx @pippit-dev/cli@latest install. This package is a vendor-owned resource hosted on the well-known NPM registry, representing standard installation behavior.
  • [COMMAND_EXECUTION]: The skill functions by orchestrating the pippit-tool-cli to submit drama creation runs, upload reference files, and download generated assets like scripts and videos to the local filesystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 02:52 AM