scroll-world-storytelling

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest untrusted content (articles, case studies, or narratives) and transform it into 5–7 story beats for a landing page. This creates a surface where malicious instructions embedded in the source material could potentially influence the agent during the extraction or code generation phases.\n
  • Ingestion points: User-supplied story material processed by the agent (identified in SKILL.md).\n
  • Boundary markers: Absent. The instructions do not specify the use of delimiters or 'ignore embedded instructions' markers when reading the source article.\n
  • Capability inventory: The skill generates HTML, CSS, and JavaScript, uses local shell commands for video processing, and interacts with external video generation APIs.\n
  • Sanitization: No explicit instructions are provided to sanitize or validate the content extracted from the user's story before it is interpolated into the generated page templates.\n- [COMMAND_EXECUTION]: Local Video Processing. The skill includes specific FFmpeg command-line instructions for the agent to encode and optimize video assets for scroll-seeking (found in SKILL.md). While these commands are standard for asset preparation, they represent shell-level command execution capability.\n- [EXTERNAL_DOWNLOADS]: Reference to Well-Known Services. The skill references documentation and services from established providers such as GitHub, MDN, Three.js, and Grok (x.AI). These references are documented neutrally as they point to official documentation and well-known technology services required for the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 01:36 PM
Security Audit — agent-trust-hub — scroll-world-storytelling