to-scenes
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external content from
BEATS.mdandNARRATION.md, which creates an inherent surface for indirect prompt injection. However, this is expected behavior for the skill's purpose and the risk is negligible due to limited capabilities. - Ingestion points: Content is read from
BEATS.mdandNARRATION.mdto be transformed into scene logic. - Boundary markers: No delimiters or instructions are used to distinguish between user data and potentially malicious embedded instructions.
- Capability inventory: The skill is restricted to reading and writing Markdown files within the local workspace. It has no access to the network, shell commands, or sensitive system environment variables.
- Sanitization: Input text is not sanitized or filtered before being processed or written to the output file.
Audit Metadata