Back to skill

Security audit

UGC Video Prompt Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward SJinn video-generation helper, with a privacy note because prompts and product images may be sent to SJinn.

Install this only if you are comfortable using SJinn for generation. Avoid supplying confidential product images, unreleased campaign details, private likenesses, or sensitive audio preferences unless you intend that material to be sent to SJinn.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs the agent to automatically submit prompts and reference images to an external SJinn service without an explicit user-consent or data-transfer warning. This can lead to unintended disclosure of user-provided content, images, or sensitive product materials to a third party, especially because generation is framed as the default next step after prompt creation.

Static analysis

No suspicious patterns detected.