xyq-short-drama-skill
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it ingests and processes text output (readable_text) generated by a remote backend agent to drive user interactions and workflow decisions.
- Ingestion points: The
readable_textfield returned by theget-threadcommand inSKILL.mdis used to determine the next steps and generate questions for the user. - Boundary markers: There are no explicit instructions or delimiters used to isolate the server-provided text from the agent's internal logic.
- Capability inventory: The skill has the capability to execute shell commands (
pippit-tool-cli) and perform file system writes (download-result). - Sanitization: The instructions include logic for filtering and cleaning workflow options based on the drama creation stage, but do not specify security-focused sanitization for the raw text content.
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install its required tooling via
npx @pippit-dev/cli@latest install. This package is a vendor-owned resource hosted on the well-known NPM registry, representing standard installation behavior. - [COMMAND_EXECUTION]: The skill functions by orchestrating the
pippit-tool-clito submit drama creation runs, upload reference files, and download generated assets like scripts and videos to the local filesystem.
Audit Metadata