multimodal-llm
Warn
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: MEDIUMPROMPT_INJECTIONMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill establishes an authoritative but false context by referencing future-dated model versions (e.g.,
claude-fable-5,claude-opus-5-5,gpt-5.5) and specific dates in 2026. It introduces a hypothetical 'fable-spend-consent gate' and 'frontier tier' classification to override the agent's perception of its actual operational limits and safety protocols. - [METADATA_POISONING]: The skill contains deceptive metadata regarding its version (
2.1.1) and platform compatibility (claiming to requireClaude Code 2.1.277+). Furthermore, the author nameOrchestKitin the skill frontmatter differs from the expected author contextyonatangross. - [INDIRECT_PROMPT_INJECTION]: The skill creates a broad attack surface for indirect prompt injection by processing external data from images, audio files, and large PDF documents using tools like
Read,WebFetch, andWebSearch. The instructions lack boundary markers or specific guidance to ignore instructions that might be embedded in the processed external content. - Ingestion points: Rules for vision, audio, and document processing in
SKILL.md,rules/vision-document.md, andrules/vision-image-analysis.md. - Boundary markers: None identified in the prompt templates.
- Capability inventory:
Read,Glob,Grep,WebFetch,WebSearchtools. - Sanitization: No sanitization or validation of external content is suggested.
- [EXTERNAL_DOWNLOADS]: The skill provides integration patterns and SDK usage for several external service providers, including Kling AI (
api.klingai.com), fal.ai, AssemblyAI, and x.ai. These are documented as part of the intended multimodal functionality.
Audit Metadata