scenario-caption-studio
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from audio transcripts and subtitle inputs, which could be exploited to manipulate the agent's behavior.
- Ingestion points: The skill ingests data via the
videoandsubtitlesparameters of themodel_scenario-caption-studiotool. - Boundary markers: There are no defined delimiters or instructions to treat ingested content as data rather than instructions.
- Capability inventory: The skill's environment includes tools for asset handling (
asset_get,asset_download), job management (model_run,jobs_wait), and references to system tools likeffmpegandnpx. - Sanitization: The skill lacks explicit instructions for sanitizing or validating the input media or text content.
Audit Metadata