vertex-ai-media-master

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection attacks because it instructs the agent to analyze external, untrusted media (video, audio, and images) while having access to sensitive tools.\n
  • Ingestion points: Analysis of video files (up to 6 hours), competitor videos, audio tracks, and images via Gemini 2.5 Pro and Imagen 4 (SKILL.md).\n
  • Boundary markers: No explicit boundary markers (e.g., XML delimiters) or instructions to ignore embedded commands are included in the prompt templates provided.\n
  • Capability inventory: The skill is configured with broad tool access, including Bash(general:*), Write, Edit, and Read (Frontmatter).\n
  • Sanitization: The instructions do not define sanitization or validation logic for the content processed or the resulting model outputs before they are used in automated workflows.\n- [SAFE]: The skill utilizes official Google Cloud SDKs (google-cloud-aiplatform, google-generativeai) and provides links to authoritative Google Cloud documentation and a trusted repository (github.com/GoogleCloudPlatform).\n- [SAFE]: Security-conscious instructions are provided, specifically recommending Google Cloud Secret Manager for API key storage and the use of VPC Service Controls for data residency.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 02:03 AM
Security Audit — agent-trust-hub — vertex-ai-media-master