multica-assistant

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by generating agent instructions and configurations from untrusted user-supplied SOP descriptions. There are no boundary markers to isolate user input from system instructions, and no sanitization is performed on the ingested content before it is used in file generation. The agent's capabilities to write files and execute scripts amplify this risk.
  • [COMMAND_EXECUTION]: The skill directs the agent to execute a local Python utility and the multica CLI. The agent is instructed to run scripts/generate_avatars.py to create image assets and use multica import commands to deploy the generated configurations to the platform runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 08:09 AM
Security Audit — agent-trust-hub — multica-assistant