muapi-storyboard
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through user-provided inputs.
- Ingestion points:
premiseandstyleinputs inSKILL.md. - Boundary markers: Absent; inputs are directly embedded in prompt strings.
- Capability inventory: Orchestrates image generation via
muapiCLI andcurlcalls. - Sanitization: Absent; input values are used without validation.
- [COMMAND_EXECUTION]: The skill utilizes the
muapiCLI tool for configuration and predictive tasks, which is standard for interacting with the MuAPI service. - [EXTERNAL_DOWNLOADS]: The skill interacts with the vendor's API endpoint at
api.muapi.aiviacurl. This communication is legitimate for the service's functionality.
Audit Metadata