faceless-explainer
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches the GSAP animation library from the jsdelivr.net CDN. This is a standard and well-known source for web development libraries, and the implementation includes Subresource Integrity (SRI) hashes to ensure the code has not been tampered with.
- [COMMAND_EXECUTION]: Local media processing is performed using FFmpeg and FFprobe. These operations are limited to looping background music and calculating audio durations within the project directory, representing legitimate use of system utilities for the skill's primary function.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided text to generate video content. This attack surface is mitigated by the structured nature of the workflow and mandatory human approval gates at key stages (storyboard and final render), preventing untrusted input from autonomously executing dangerous actions.
- [DATA_EXPOSURE]: The skill does not access sensitive system files or credentials. Authentication status for external APIs (like HeyGen) is checked using the platform's native CLI, and no secrets are hardcoded or exfiltrated.
Audit Metadata