scenario
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied prompts and media files, creating a potential surface for indirect instructions to influence agent behavior. * Ingestion points: Prompt fields in
model_runand file contents inupload_asset. * Boundary markers: None defined. * Capability inventory: Network access toscenario.comand file system read/write access. * Sanitization: No explicit content filtering mentioned. - [EXTERNAL_DOWNLOADS]: The skill retrieves data and interacts with the vendor's official domain at
mcp.scenario.com. * Evidence: Endpoint URLs and asset download links. - [COMMAND_EXECUTION]: Instructions describe how to use shell commands for installation and asset retrieval. * Evidence: Setup commands like
claude mcp addand usage ofcurl -Lfor file downloads.
Audit Metadata