creative-generation-agent
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
ImageGenerationAgentinexamples/image_generation.pyfetches pre-trained model weights from a well-known model registry using therunwayml/stable-diffusion-v1-5identifier. - [INDIRECT_PROMPT_INJECTION]: The skill uses user-supplied strings to construct prompts for generative models, which creates a surface for potential indirect prompt injection attacks.
- Ingestion points: User-supplied topics and prompts are ingested in
examples/meme_generator.py,examples/podcast_producer.py, andexamples/image_generation.py. - Boundary markers: The prompt templates in the
PodcastScriptGeneratorandMemeGenerationAgentclasses do not employ delimiters or instructions to prevent the model from following commands embedded within the user data. - Capability inventory: The skill produces media content (audio, images, text) and does not expose sensitive system operations to the outputs of these generative models across its modules including
music_generation.pyandpodcast_producer.py. - Sanitization: A
ContentModeratorclass is provided inscripts/content_moderation.pyto filter content, but its implementation methods are currently empty stubs.
Audit Metadata