create-concepts
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses specialized MCP tools like mcp__motion__get_creative_insights to retrieve structured marketing data.
- [EXTERNAL_DOWNLOADS]: Fetches external content such as competitor ad data and transcripts to inform creative analysis.
- [SAFE]: Accesses local configuration files (motion-creative.config.md) and internal reference documents to apply quality standards.
- [PROMPT_INJECTION]: The skill processes external transcripts which presents a surface for indirect prompt injection. Ingestion points: External data enters through get_creative_transcript and competitor brand context tools. Boundary markers: None identified in external content processing. Capability inventory: Limited to Read and AskUserQuestion tools without file-write or shell access. Sanitization: No explicit filtering of external content mentioned.
Audit Metadata