to-scenes

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external content from BEATS.md and NARRATION.md, which creates an inherent surface for indirect prompt injection. However, this is expected behavior for the skill's purpose and the risk is negligible due to limited capabilities.
  • Ingestion points: Content is read from BEATS.md and NARRATION.md to be transformed into scene logic.
  • Boundary markers: No delimiters or instructions are used to distinguish between user data and potentially malicious embedded instructions.
  • Capability inventory: The skill is restricted to reading and writing Markdown files within the local workspace. It has no access to the network, shell commands, or sensitive system environment variables.
  • Sanitization: Input text is not sanitized or filtered before being processed or written to the output file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 03:37 PM
Security Audit — agent-trust-hub — to-scenes