scenario-caption-studio

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from audio transcripts and subtitle inputs, which could be exploited to manipulate the agent's behavior.
  • Ingestion points: The skill ingests data via the video and subtitles parameters of the model_scenario-caption-studio tool.
  • Boundary markers: There are no defined delimiters or instructions to treat ingested content as data rather than instructions.
  • Capability inventory: The skill's environment includes tools for asset handling (asset_get, asset_download), job management (model_run, jobs_wait), and references to system tools like ffmpeg and npx.
  • Sanitization: The skill lacks explicit instructions for sanitizing or validating the input media or text content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 07:46 AM
Security Audit — agent-trust-hub — scenario-caption-studio