design-visual-storyteller
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill defines a workflow that ingests data from local files, which represents an attack surface for indirect prompt injection.
- Ingestion points: The workflow in SKILL.md references reading files from 'ai/memory-bank/' and 'public/images/'.
- Boundary markers: There are no explicit delimiters or instructions for the agent to ignore embedded commands within these files.
- Capability inventory: The documentation describes the use of filesystem tools like cat, ls, and grep to process content.
- Sanitization: No sanitization or validation of the data ingested from the memory bank files is mentioned.
Audit Metadata