skills/scenario-labs/skills/scenario/Gen Agent Trust Hub

scenario

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied prompts and media files, creating a potential surface for indirect instructions to influence agent behavior. * Ingestion points: Prompt fields in model_run and file contents in upload_asset. * Boundary markers: None defined. * Capability inventory: Network access to scenario.com and file system read/write access. * Sanitization: No explicit content filtering mentioned.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves data and interacts with the vendor's official domain at mcp.scenario.com. * Evidence: Endpoint URLs and asset download links.
  • [COMMAND_EXECUTION]: Instructions describe how to use shell commands for installation and asset retrieval. * Evidence: Setup commands like claude mcp add and usage of curl -L for file downloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 07:46 AM
Security Audit — agent-trust-hub — scenario