multimodal-llm

Warn

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: MEDIUMPROMPT_INJECTIONMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill establishes an authoritative but false context by referencing future-dated model versions (e.g., claude-fable-5, claude-opus-5-5, gpt-5.5) and specific dates in 2026. It introduces a hypothetical 'fable-spend-consent gate' and 'frontier tier' classification to override the agent's perception of its actual operational limits and safety protocols.
  • [METADATA_POISONING]: The skill contains deceptive metadata regarding its version (2.1.1) and platform compatibility (claiming to require Claude Code 2.1.277+). Furthermore, the author name OrchestKit in the skill frontmatter differs from the expected author context yonatangross.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a broad attack surface for indirect prompt injection by processing external data from images, audio files, and large PDF documents using tools like Read, WebFetch, and WebSearch. The instructions lack boundary markers or specific guidance to ignore instructions that might be embedded in the processed external content.
  • Ingestion points: Rules for vision, audio, and document processing in SKILL.md, rules/vision-document.md, and rules/vision-image-analysis.md.
  • Boundary markers: None identified in the prompt templates.
  • Capability inventory: Read, Glob, Grep, WebFetch, WebSearch tools.
  • Sanitization: No sanitization or validation of external content is suggested.
  • [EXTERNAL_DOWNLOADS]: The skill provides integration patterns and SDK usage for several external service providers, including Kling AI (api.klingai.com), fal.ai, AssemblyAI, and x.ai. These are documented as part of the intended multimodal functionality.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 25, 2026, 03:08 PM
Security Audit — agent-trust-hub — multimodal-llm