muapi-storyboard — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited muapi-storyboard (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Generate N keyframes for a short story or scene sequence (image only, no video).
| Name | Type | Required | Default | Description |
|---|---|---|---|---|
premise | text | yes | — | One-line story premise (e.g. "lonely robot finds a tiny mechanical bird friend"). |
scenes | int | no | 6 | Number of keyframes to produce. |
style | text | no | cinematic, photoreal, soft lighting, 16:9 | Visual style tags applied to every keyframe. |
Use the plan to dispatch all N keyframes in a single parallel layer.
premise into {{scenes}} story beats with a clear arc:setup → inciting moment → escalation → climax → resolution.
appearance, same world).
muapi image generate node (model=nano-banana-2, aspect_ratio=16:9):"<beat description>. {{style}}".depends_on between keyframes).If the user wants video, suggest the music-video skill afterward.
("a small rusty humanoid robot with…") rather than relying on the model to remember.
storyboard, keyframes, scene sequence, story panels
muapi CLI commands. Use muapi auth configure first if MUAPI_API_KEY is unset.curl -X POST https://api.muapi.ai/api/v1/<endpoint> -H "x-api-key: $MUAPI_API_KEY" -H 'content-type: application/json' -d '{...}' and poll with muapi predict wait <request_id>.{{input_name}} placeholders with the user's actual inputs before issuing each call.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.